WorksheetsLinkedin CyberSec Test
Total questions: 20
Worksheet time: 30mins
According to the shared responsibility model, which cloud computing model places the most responsibility on the cloud service provider (CSP)?
Hybrid Cloud
Software as a Service (SaaS)
Platform as a Service (PaaS)
Infrastructure as a Service (IaaS)
Which option removes the risk of multitenancy in cloud computing?
PaaS
public cloud
private cloud
IaaS
Your organization recently implemented a unified messaging solution and VoIP phones on every desktop. You are responsible for researching the vulnerabilities of the VoIP system. Which type of attack are VoIP phones most vulnerable to experiencing?
denial-of-service
brute force attacks
malware
buffer overflow
Which security control cannot produce an active response to a security event?
cloud access security broker (CASB)
intrusion prevention system (IPS)
intrusion detection system (IDS)
next generation firewall
Packet sniffer is also called \_.
SIEM
UTM
protocol analyzer
data sink
Which option tests code while it is in operation?
code review
code analysis
static analysis
dynamic analysis
Which option describes testing that individual software developers can conduct on their own code?
gray box testing
integration testing
white box testing
unit testing
In black box penetration testing, what information is provided to the tester about the target environment?
none
limited details of server and network infrastructure
all information
limited details of server infrastructure
Which security control can best protect against shadow IT by identifying and preventing use of unsanctioned cloud apps and services?
intrusion prevention system (IPS)
next generation firewall
cloud access security broker (CASB)
intrusion detection system (IDS)
Which option describes the best defense against collusion?
monitoring of normal employee system and data access patterns
applying system and application updates regularly
fault tolerant infrastructure and data redundancy
separation of duties and job rotation
During a penetration test, you find a file containing hashed passwords for the system you are attempting to breach. Which type of attack is most likely to succeed in accessing the hashed passwords in a reasonable amount of time?
rainbow table attack
pass-the-hash attack
password spray attack
brute force attack
Which area is DMZ?
4
1
2
3
You configure an encrypted USB drive for a user who needs to deliver a sensitive file at an in-person meeting. What type of encryption is typically used to encrypt the file?
file hash
asymmetric encryption
digital signature
symmetric encryption
What is the difference between DRP and BCP
DRP works to keep a business up and running despite a disaster. BCP works to restore the original business capabilities.
BCP works to keep a business up and running despite a disaster. DRP works to restore the original business capabilities.
BCP is part of DRP.
DRP is part of BCP.
Which aspect of cybersecurity do Distributed Denial of Service (DDoS) attacks affect the most?
non-repudiation
integrity
availability
confidentiality
You need to recommend a solution to automatically assess your cloud-hosted VMs against CIS benchmarks to identify deviations from security best practices. What type of solution should you recommend?
Cloud Security Posture Management (CSPM)
Intrusion Detection and Prevention System (IDPS)
Cloud Workload Protection Platforms (CWPP)
Cloud Access Security Brokers (CASBs)
\_ validates the integrity of data files.
Compression
Hashing
Symmetric encryption
Stenography
Which is an example of privacy regulation at the state government level in the U.S.?
CCPA
GDPR
NIST Privacy Framework
OSPF
what is the term for the policies and technologies implemented to protect, limit, monitor, audit, and govern identities with access to sensitive data and resources?
identity and access management (IAM)
privileged account management (PAM)
authentication and authorization
least privilege
You have configured audit settings in your organization's cloud services in the event of a security incident. What type of security control is an audit trail?
preventive control
detective control
directive control
corrective control
