Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

SiberAbluka 601-630

Total questions: 26

Worksheet time: 52mins

Name
Class
Date
1.

NO.601 Which of tre following would BEST identity and remediate a catatoss

event in an enterprise using third-pany, web-based services and file-sharing platanmns?

a)

(A). SIEM

b)

(B). CASE

c)

(C). UTM

d)

(D). EDR

2.

NO.602 An engineer is setting up a VDI environment for a factory tocation, and the business wants to deploy a low-cost solution to enadle users on the shop floor to log in to the VDI environment directly. Which of the following should the engineer select to meet these requirements?

a)

(A). Laptops

b)

(B). Containers

c)

(C). Thin clients

d)

(D). Workstations

3.

NO.603 A security analyst is reviewing the following command-line output:

Which of the following Is the analyst observing?

a)

(A). IGMP spoofing

b)

(B). URL redirection

c)

(C). MAG address cloning

d)

(D). DNS poisoning

4.

NO.604 Which of the following should a data owner require all personnel to sign to legally protect intellectual property?

a)

(A). An NDA

b)

(B). An AUP

c)

(C). An ISA

d)

(D). An MOU

5.

NO.605 A security administrator needs to inspect in-transit files on the enterprise network to search for Pll, credit card data, and classification words. Which of the following would be the BEST to use?

a)

(A). IDS solution

b)

(B). EDR solution

c)

(C). HIPS software solution

d)

(D). Network DLP solution

6.

NO.606 A security analyst must determine if either SSH or Telnet is being used to log in to servers. Which of the following should the analyst use?

a)

(A). logger

b)

(B). Metasploit

c)

(C). tcpdump

d)

(D). netstat

7.

NO.607 A routine audit of medical billing claims revealed that several claims were submitted

without the subscriber's knowledge. A review of the audit logs for the medical billing company's

system indicated a company employee downloaded customer records and adjusted the direct

deposit information to a personal bank account. Which of the following does this action describe?

a)

(A). Insider threat

b)

(B). Social engineering

c)

(C). Third-party risk

d)

(D). Data breach

8.

NO.608 A security administrator is trying to determine whether a server is vulnerable to a range of attacks. After using a tool, the administrator obtains the following output: Which of the following attacks was successfully implemented based on the output?

a)

(A). Memory leak

b)

(B). Race conditions

c)

(C). SQL injection

d)

(D). Directory traversal

9.

NO.611 A Chief Security Officer (CSO) is concerned about the volume and integrity of sensitive

information that is exchanged between the organization and a third party through email. The CSO is particularly concerned about an unauthorized party who is intercepting information that is in transit between the two organizations. Which of the following would address the CSO's concerns?

a)

(A). SPF

b)

(B). DMARC

c)

(C). SSL

d)

(D). DKIM

e)

(E). TLS

10.

NO.612 Which of the following BEST describes the MFA attribute that requires a callback on a predefined landline?

a)

(A). Something you exhibit

b)

(B). Something you can do

c)

(C). Someone you know

d)

(D). Somewhere you are

11.

NO.613 A multinational organization that offers web-based services has datacenters that are located

only in the United States; however, a large number of its customers are in Australia, Europe, and Chin

a. Payments for services are managed bya third party in the United Kingdom that specializes in

payment gateways. The management team is concerned the organization is not compliant with

privacy laws that cover some of its customers. Which of the following frameworks should the

management team follow?

a)

(A). Payment Card Industry Data Security Standard

b)

(B). Cloud Security Alliance Best Practices

c)

(C). ISO/IEC 27032 Cybersecurity Guidelines

d)

(D). General Data Protection Regulation

12.

NO.614 The concept of connecting a user account across the systems of multiple enterprises is BEST known as:

a)

(A). federation.

b)

(B). a remote access policy.

c)

(C). multifactor authentication.

d)

(D). single sign-on.

13.

NO.615 A Chief Executive Officer (CEO) is dissatisfied with the level of service from the company's new service provider. The service provider is preventing the CEO from sending email from a work account to a personal account. Which of the following types of service providers is being used?

a)

(A).

Telecommunications service provider

b)

(B).

Cloud service provider

c)

(C).

Master managed service provider

d)

(D).

Managed security service provider

14.

NO.616 nteping a secure area requires passing though two doors, both of which require someone who is already inside to initiate access. Which of the following types of physical security controls does this describe?

a)

(A). Cameras

b)

B: Faraday cage

c)

(C). Access control vestibule

d)

(D). Sensors

15.

NO.618 An attacker was eavesdropping on a user who was shopping online. The attacker was able to spoof the IP address associated with the shopping site. Later, the user received an email regarding the credit card statement with unusual purchases. Which of the following attacks took place?

a)

(A). On-path attack

b)

(B). Protocol poisoning

c)

(C). Domain hijacking

d)

(D). Bluejacking

16.

NO.620 A security administrator has noticed unusual activity occurring between different global instances and workloads and needs to identify the source of the unusual traffic. Which of the following log sources would be BEST to show the source of the unusual traffic?

a)

(A). HIDS

b)

(B).UEBA

c)

(C). CASB

d)

(D). VPC

17.

NO.621 A manufacturing company has several one-off legacy information systems that cannot be migrated to a newer OS due to software compatibility issues. The OSs are still supported by the vendor, but the industrial software is no longer supported. The Chief Information Security Officer (CISO) has created a resiliency plan for these systems that will allow OS patches to be installed in a non-production environment, while also creating backups of the systems for recovery. Which of the following resiliency techniques will provide these capabilities?

a)

(A). Redundancy

b)

(B). RAID 1+5

c)

(C). Virtual machines

d)

(D). Full backups

18.

NO.622 Whictpof the following will MOST likely cause machine-learning and Al enabled systems to operate with unintended consequences?

a)

(A). Stored procedures

b)

(B). Buffer overflows

c)

(C). Data bias

d)

(D). Code reuse

19.

NO.623 A security operations analyst is using the company's SIEM solution to correlate alerts. Which of the following stages of the incident response process is this an example of?

a)

(A). Eradication

b)

(B). Recovery

c)

(C). Identification

d)

(D). Preparation

20.

NO.624 Which of the following terms should be included in a contract to help a company monitor the ongoing security maturity of a new vendor?

a)

(A). A right-to-audit clause allowing for annual security audits

b)

(B). Requirements for event logs to be kept for a minimum of 30 days

c)

(C). Integration of threat intelligence in the company's AV

d)

(D). A data-breach clause requiring disclosure of significant data loss

21.

NO.625 An incident, which is affecting dozens of systems, involves malware that reaches out to an Internet service for rules and updates. The IP addresses for the Internet host appear to be different in each case. The organization would like to determine a common IoC to support response and recovery actions. Which of the following sources of information would BEST support this solution?

a)

(A). Web log files

b)

(B). Browser cache

c)

(C). DNS query logs

d)

(D). Antivirus

22.

NO.626 Which of the following represents a biometric FRR?

a)

(A). Authorized users being denied access

b)

(B). Users failing to enter the correct PIN

c)

(C). The denied and authorized numbers being equal

d)

(D). The number of unauthorized users being granted access

23.

NO.627 Aweb server administrator has redundant servers and needs to ensure failover to the secondary server when the primary server goes down. Which of the following should the administrator implement to avoid disruption?

a)

(A). NIC teaming

b)

(B). High availability

c)

(C). Dual power supply

d)

(D). laaS

24.

NO.628 An organization regularly scans its infrastructure for missing security patches but is concerned about hackers gaining access to the scanner's account. Which of the following would be BEST to minimize this risk?

a)

(A). Require a complex, eight-character password that is updated every 90 days.

b)

(B). Perform only non-intrusive scans of workstations.

c)

(C). Use non-credentialed scans against high-risk servers.

d)

(D). Log and alert on unusual scanner account logon times.

25.

NO.629 Which of the following is assured when a user signs an email using a private key?

a)

(A). Non-repudiation

b)

(B). Confidentiality

c)

(C). Availably

d)

(D). Authentication

26.

NO.630 The process of passively gathering information prior to launching a cyberattack is called:

a)

(A). Tailgating

b)

(B). Reconnaissance

c)

(C). Pharming

d)

(D). Prepending