wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

SEC+ Ch.11 Review Test

Total questions: 15

Worksheet time: 8mins

Name
Class
Date
1.

Management within your organization wants to ensure that users understand the rules of behavior when they access the organization’s computer systems and networks. Which of the following BEST describes what they would implement to meet this requirement?

a)

AUP

b)

NDA

c)

SLA

d)

MSA

2.

Management recently decided to upgrade the organization’s security policy. Among other items, they want to implement a policy that will reduce the risk of personnel within the organization colluding to embezzle company funds. Which of the following is the BEST choice to meet this need?

a)

AUP

b)

Training

c)

Mandatory vacations

d)

Background check

3.

Lisa is a training instructor, and she maintains a training lab with 16 computers. She has enough rights and permissions on these machines to configure them as needed for classes. However, she does not have the rights to add them to the organization’s domain. Which of the following choices BEST describes the reasoning for this?

a)

Least privilege

b)

MSA

c)

Diversity of training

d)

Offboarding

4.

Your organization includes a software development division within the IT department. One developer writes and maintains applications for the Sales and Marketing departments. A second developer writes and maintains applications for the Payroll department. Once a year, they switch roles for at least a month. What is the purpose of this practice?

a)

To enforce a separation of duties policy

b)

To enforce a mandatory vacation policy

c)

To enforce a job rotation policy

d)

To enforce an acceptable use policy

5.

Your organization recently suffered a costly malware attack. Management wants to take steps to prevent damage from malware in the future. Which of the following phases of common incident response procedures is the BEST phase to address this?

a)

Preparation

b)

Identification

c)

Containment

d)

Eradication

6.

An incident response team is following typical incident response procedures. Which of the following phases is the BEST choice for analyzing an incident to identify steps to prevent a reoccurrence of the incident?

a)

Preparation

b)

Identification

c)

Eradication

d)

Lessons learned

7.

After a recent cybersecurity incident resulting in a significant loss, your organization decided to create a security policy for incident response. Which of the following choices is the BEST choice to include in the policy when an incident requires confiscation of a physical asset?

a)

Ensure hashes are taken first.

b)

Maintain the order of volatility.

c)

Keep a record of everyone who took possession of the physical asset.

d)

Require interviews of all witnesses present when the asset is confiscated.

8.

A forensic analyst was told of a suspected attack on a Virginia-based webserver from IP address 72.52.230.233 at 01:23:45 GMT. However, after investigating the logs, he doesn’t see any traffic from that IP at that time. Which of the following is the MOST likely reason why the analyst was unable to identify the traffic?

a)

He did not account for the time offset.

b)

He did not capture an image.

c)

The IP address has expired.

d)

The logs were erased when the system was rebooted.

9.

Homer called the help desk complaining his computer is giving random errors. Cybersecurity professionals suspect his system is infected with malware and decide to use digital forensic methods to acquire data on his system. Which of the following should be collected before turning the system off? (Choose TWO.)

a)

Image of disk

b)

RAM

c)

OS

d)

ROM

e)

Cache

10.

After a recent incident, a forensic analyst was given several hard drives to analyze. Which of the following actions should she take FIRST?

a)

Capture drive images for integrity.

b)

Take hashes for provenance.

c)

Review the logs on the disks.

d)

Create a chain of custody document.

11.

A health care organization manages several hospitals and medical facilities within a state, and they have treated thousands of patients who have suffered from a recent viral outbreak. Doctors from another state are performing studies of this virus and would like to access the information that the health care organization has amassed. Management has authorized the release of this information but has mandated that the data cannot reveal any personal information about patients. Which of the following methods will BEST meet these requirements?

a)

Pseudo-anonymization

b)

Tokenization

c)

Encryption

d)

Masking

12.

An urban hospital has recently treated hundreds of patients after a viral outbreak. Researchers trying to learn more about the virus have asked the hospital for information on treatment methods they used and their outcomes. The hospital management has asked the IT department to remove all personal information about patients before releasing this data. Which of the following methods will BEST meet these requirements?

a)

Anonymization

b)

Pseudo-anonymization

c)

Tokenization

d)

Data minimization

13.

Investigations have shown that several recent security incidents originated after employees responded inappropriately to malicious emails. The IT department has sent out multiple emails describing what to do with these emails, but employees continue to respond inappropriately. The chief information officer has directed the Human Resources department to find and implement a solution that will increase user awareness and reduce these incidents. Which of the following would be the BEST solution?

a)

Offboarding

b)

Least privilege

c)

Gamification

d)

Role-based training

14.

Your organization is updating the data policy, and management wants to ensure that employees get training on their responsibilities based on their role. Which of the following BEST describes the responsibilities of data owners and indicates what training they need?

a)

Ensuring data is backed up in accordance with the data policy

b)

Ensuring data is classified and labeled correctly

c)

Complying with laws related to privacy

d)

Understanding common threats, such as malware and phishing attacks

15.

Organizations that conduct business in the EU must have a position within the organization that can act as an independent advocate for the proper care and use of customer information. Which of the following BEST identifies this position?

a)

Data owner

b)

Data custodian

c)

Data processor

d)

Data protection officer