Font size
WorksheetsSEC+ Ch.11 Review Test
Total questions: 15
Worksheet time: 8mins
Management within your organization wants to ensure that users understand the rules of behavior when they access the organization’s computer systems and networks. Which of the following BEST describes what they would implement to meet this requirement?
AUP
NDA
SLA
MSA
Management recently decided to upgrade the organization’s security policy. Among other items, they want to implement a policy that will reduce the risk of personnel within the organization colluding to embezzle company funds. Which of the following is the BEST choice to meet this need?
AUP
Training
Mandatory vacations
Background check
Lisa is a training instructor, and she maintains a training lab with 16 computers. She has enough rights and permissions on these machines to configure them as needed for classes. However, she does not have the rights to add them to the organization’s domain. Which of the following choices BEST describes the reasoning for this?
Least privilege
MSA
Diversity of training
Offboarding
Your organization includes a software development division within the IT department. One developer writes and maintains applications for the Sales and Marketing departments. A second developer writes and maintains applications for the Payroll department. Once a year, they switch roles for at least a month. What is the purpose of this practice?
To enforce a separation of duties policy
To enforce a mandatory vacation policy
To enforce a job rotation policy
To enforce an acceptable use policy
Your organization recently suffered a costly malware attack. Management wants to take steps to prevent damage from malware in the future. Which of the following phases of common incident response procedures is the BEST phase to address this?
Preparation
Identification
Containment
Eradication
An incident response team is following typical incident response procedures. Which of the following phases is the BEST choice for analyzing an incident to identify steps to prevent a reoccurrence of the incident?
Preparation
Identification
Eradication
Lessons learned
After a recent cybersecurity incident resulting in a significant loss, your organization decided to create a security policy for incident response. Which of the following choices is the BEST choice to include in the policy when an incident requires confiscation of a physical asset?
Ensure hashes are taken first.
Maintain the order of volatility.
Keep a record of everyone who took possession of the physical asset.
Require interviews of all witnesses present when the asset is confiscated.
A forensic analyst was told of a suspected attack on a Virginia-based webserver from IP address 72.52.230.233 at 01:23:45 GMT. However, after investigating the logs, he doesn’t see any traffic from that IP at that time. Which of the following is the MOST likely reason why the analyst was unable to identify the traffic?
He did not account for the time offset.
He did not capture an image.
The IP address has expired.
The logs were erased when the system was rebooted.
Homer called the help desk complaining his computer is giving random errors. Cybersecurity professionals suspect his system is infected with malware and decide to use digital forensic methods to acquire data on his system. Which of the following should be collected before turning the system off? (Choose TWO.)
Image of disk
RAM
OS
ROM
Cache
After a recent incident, a forensic analyst was given several hard drives to analyze. Which of the following actions should she take FIRST?
Capture drive images for integrity.
Take hashes for provenance.
Review the logs on the disks.
Create a chain of custody document.
A health care organization manages several hospitals and medical facilities within a state, and they have treated thousands of patients who have suffered from a recent viral outbreak. Doctors from another state are performing studies of this virus and would like to access the information that the health care organization has amassed. Management has authorized the release of this information but has mandated that the data cannot reveal any personal information about patients. Which of the following methods will BEST meet these requirements?
Pseudo-anonymization
Tokenization
Encryption
Masking
An urban hospital has recently treated hundreds of patients after a viral outbreak. Researchers trying to learn more about the virus have asked the hospital for information on treatment methods they used and their outcomes. The hospital management has asked the IT department to remove all personal information about patients before releasing this data. Which of the following methods will BEST meet these requirements?
Anonymization
Pseudo-anonymization
Tokenization
Data minimization
Investigations have shown that several recent security incidents originated after employees responded inappropriately to malicious emails. The IT department has sent out multiple emails describing what to do with these emails, but employees continue to respond inappropriately. The chief information officer has directed the Human Resources department to find and implement a solution that will increase user awareness and reduce these incidents. Which of the following would be the BEST solution?
Offboarding
Least privilege
Gamification
Role-based training
Your organization is updating the data policy, and management wants to ensure that employees get training on their responsibilities based on their role. Which of the following BEST describes the responsibilities of data owners and indicates what training they need?
Ensuring data is backed up in accordance with the data policy
Ensuring data is classified and labeled correctly
Complying with laws related to privacy
Understanding common threats, such as malware and phishing attacks
Organizations that conduct business in the EU must have a position within the organization that can act as an independent advocate for the proper care and use of customer information. Which of the following BEST identifies this position?
Data owner
Data custodian
Data processor
Data protection officer
