Font size
WorksheetsSEC+ Ch.8 Review Test
Total questions: 15
Worksheet time: 8mins
A server within your organization has suffered six hardware failures in the past year. IT management personnel have valued the server at $4,000, and each failure resulted in a 10 percent loss. What is the ALE?
$400
$2400
$4000
$6000
Maggie is performing a risk assessment on a database server. While doing so, she created a document showing all the known risks to this server, along with the risk score for each risk. Which of the following BEST identifies the name of this document?
Qualitative risk assessment
Quantitative risk assessment
Risk register
Residual risk
Your organization hosts an e-commerce website used to sell digital products. You are tasked with evaluating all the elements used to support this website. What are you performing?
Quantitative assessment
Qualitative assessment
Threat hunting
Supply chain assessment
Which of the following elements are used as part of threat hunting?
(Choose two.)
Intelligence fusion
Vulnerability scan
Advisories and bulletins
Configuration review
Maggie suspects that a server may be running unnecessary services. Which of the following tools is the BEST choice to identify the services running on the server?
Dnsenum
IP scanner
Passive reconnaissance
Nmap
You want to identify all the services running on a server in your network.
Which of the following tools is the BEST choice to meet this goal?
Penetration test
Protocol analyzer
Non-credentialed scan
Port scanner
You recently completed a vulnerability scan on a database server. The scan didn’t report any issues. However, you know that it is missing a patch. The patch wasn’t applied because it causes problems with the database application. Which of the following BEST describes this?
False negative
False positive
Credential scan
Non-credentialed scan
You suspect that a database server used by a web application is not up to date with current patches. Which of the following is the BEST action to take to verify the server has up-to-date patches?
Network scan
Port scan
Protocol analyzer
Vulnerability scan
Lisa periodically runs vulnerability scans on the organization’s network. Lately, she has been receiving many false positives. Which of the following actions can help reduce the false positives?
Run the scans as credentialed scans.
Run the scans as non-credentialed scans.
Run the scans using passive reconnaissance.
Run the scans using active reconnaissance.
Your organization has hired outside penetration testers to identify internal network vulnerabilities. After successfully exploiting vulnerabilities in a single computer, the testers attempt to access other systems within the network. Which of the following BEST describes their current actions?
Partially known environment testing
Persistence
Lateral movement
Privilege escalation
Bart, a database administrator in your organization, told you about recent attacks on the network and how they have been disrupting services and network connectivity. In response, he said he has been using Nmap to run vulnerability scans and identify vulnerabilities. Which of the following is wrong with this scenario?
The database administrator was pivoting from his primary job.
A network scan wasn’t done first.
Scans weren’t done as credentialed scans.
Rules of engagement weren’t obtained.
Your organization outsourced the development of a software module to modify an existing proprietary application’s functionality. The developer completed the module and is now testing it with the entire application.
What type of testing is the developer performing?
Known environment
Unknown environment
Partially known environment
Red team
The IT department at your organization recently created an isolated test network that mimics the DMZ. They then hired an outside company to perform a simulated cyberattack on this isolated test network as part of a testing campaign. Which of the following BEST describes the role of personnel from the outside company?
Red team
Blue team
Purple team
White team
Your organization is setting up an e-commerce site to sell products online. Management wants to ensure the website can accept credit cards for payment. Which of the following standards are they MOST likely to follow?
ISO 27001
PCI DSS
ISO 31000
SSAE SOC 2 Type I
Your organization recently purchased and deployed an IDS within the network. Security administrators want to verify it will detect a syn stealth scan. Which of the following tools will BEST meet your need?
Tcpreplay
Tcpdump
Wireshark
Netcat
