wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

SEC+ Ch.8 Review Test

Total questions: 15

Worksheet time: 8mins

Name
Class
Date
1.

A server within your organization has suffered six hardware failures in the past year. IT management personnel have valued the server at $4,000, and each failure resulted in a 10 percent loss. What is the ALE?

a)

$400

b)

$2400

c)

$4000

d)

$6000

2.

Maggie is performing a risk assessment on a database server. While doing so, she created a document showing all the known risks to this server, along with the risk score for each risk. Which of the following BEST identifies the name of this document?

a)

Qualitative risk assessment

b)

Quantitative risk assessment

c)

Risk register

d)

Residual risk

3.

Your organization hosts an e-commerce website used to sell digital products. You are tasked with evaluating all the elements used to support this website. What are you performing?

a)

Quantitative assessment

b)

Qualitative assessment

c)

Threat hunting

d)

Supply chain assessment

4.

Which of the following elements are used as part of threat hunting?

(Choose two.)

a)

Intelligence fusion

b)

Vulnerability scan

c)

Advisories and bulletins

d)

Configuration review

5.

Maggie suspects that a server may be running unnecessary services. Which of the following tools is the BEST choice to identify the services running on the server?

a)

Dnsenum

b)

IP scanner

c)

Passive reconnaissance

d)

Nmap

6.

You want to identify all the services running on a server in your network.

Which of the following tools is the BEST choice to meet this goal?

a)

Penetration test

b)

Protocol analyzer

c)

Non-credentialed scan

d)

Port scanner

7.

You recently completed a vulnerability scan on a database server. The scan didn’t report any issues. However, you know that it is missing a patch. The patch wasn’t applied because it causes problems with the database application. Which of the following BEST describes this?

a)

False negative

b)

False positive

c)

Credential scan

d)

Non-credentialed scan

8.

You suspect that a database server used by a web application is not up to date with current patches. Which of the following is the BEST action to take to verify the server has up-to-date patches?

a)

Network scan

b)

Port scan

c)

Protocol analyzer

d)

Vulnerability scan

9.

Lisa periodically runs vulnerability scans on the organization’s network. Lately, she has been receiving many false positives. Which of the following actions can help reduce the false positives?

a)

Run the scans as credentialed scans.

b)

Run the scans as non-credentialed scans.

c)

Run the scans using passive reconnaissance.

d)

Run the scans using active reconnaissance.

10.

Your organization has hired outside penetration testers to identify internal network vulnerabilities. After successfully exploiting vulnerabilities in a single computer, the testers attempt to access other systems within the network. Which of the following BEST describes their current actions?

a)

Partially known environment testing

b)

Persistence

c)

Lateral movement

d)

Privilege escalation

11.

Bart, a database administrator in your organization, told you about recent attacks on the network and how they have been disrupting services and network connectivity. In response, he said he has been using Nmap to run vulnerability scans and identify vulnerabilities. Which of the following is wrong with this scenario?

a)

The database administrator was pivoting from his primary job.

b)

A network scan wasn’t done first.

c)

Scans weren’t done as credentialed scans.

d)

Rules of engagement weren’t obtained.

12.

Your organization outsourced the development of a software module to modify an existing proprietary application’s functionality. The developer completed the module and is now testing it with the entire application.

What type of testing is the developer performing?

a)

Known environment

b)

Unknown environment

c)

Partially known environment

d)

Red team

13.

The IT department at your organization recently created an isolated test network that mimics the DMZ. They then hired an outside company to perform a simulated cyberattack on this isolated test network as part of a testing campaign. Which of the following BEST describes the role of personnel from the outside company?

a)

Red team

b)

Blue team

c)

Purple team

d)

White team

14.

Your organization is setting up an e-commerce site to sell products online. Management wants to ensure the website can accept credit cards for payment. Which of the following standards are they MOST likely to follow?

a)

ISO 27001

b)

PCI DSS

c)

ISO 31000

d)

SSAE SOC 2 Type I

15.

Your organization recently purchased and deployed an IDS within the network. Security administrators want to verify it will detect a syn stealth scan. Which of the following tools will BEST meet your need?

a)

Tcpreplay

b)

Tcpdump

c)

Wireshark

d)

Netcat