WorksheetsSecurity + quiz 14
Total questions: 14
Worksheet time: 8mins
A nuclear plant was the victim of a recent attack, and all the networks were air gapped. A subsequent investigation revealed a worm as the source of the issue. Which of the following BEST explains what happened?
A malicious USB was introduced by an unsuspecting employee.
The ICS firmware was outdated
A local machine has a RAT installed.
The HVAC was connected to the maintenance vendor.
Under GDPR, which of the following is MOST responsible for the protection of privacy and website user rights?
The data protection officer
The data processor
The data owner
The data controller
A user recent an SMS on a mobile phone that asked for bank delays. Which of the following social-engineering techniques was used in this case?
SPIM
Vishing
Spear phishing
Smishing
A security administrator needs to create a RAIS configuration that is focused on high read speeds and fault tolerance. It is unlikely that multiple drivers will fail simultaneously. Which of the following RAID configurations should the administration use?
RA1D 0
RAID1
RAID 5
RAID 10
A user is concerned that a web application will not be able to handle unexpected or random input without crashing. Which of the following BEST describes the type of testing the user should perform?
Code signing
Fuzzing
Manual code review
Dynamic code analysis
A security administrator checks the table of a network switch, which shows the following output:
VLAN Physical Address Type Port
1 001a:42ff:5113 Dynamic GEO/5
1 0faa:abcf:ddee Dynamic GEO/5
1 c6a9:6b16:750e Dynamic GEO/5
1 a3aa:b6a3:1212 Dynamic GEO/5
1 8025:2ad8:bfac Dynamic GEO/5
1 b839:f995:a00a Dynamic GEO/5
Which of the following is happening to this switch?
MAC Flooding
DNS poisoning
MAC cloning
ARP poisoning
A company needs to centralize its logs to create a baseline and have visibility on its security events. Which of the following technologies will accomplish this objective?
Security information and event management
A web application firewall
A vulnerability scanner
A next-generation firewall
The SOC is reviewing process and procedures after a recent incident. The review indicates it took more than 30 minutes to determine that quarantining an infected host was the best course of action. The allowed the malware to spread to additional hosts before it was contained. Which of the following would be BEST to improve the incident response process?
Updating the playbooks with better decision points
Dividing the network into trusted and untrusted zones
Providing additional end-user training on acceptable use
Implementing manual quarantining of infected hosts
An organization has been experiencing outages during holiday sales and needs to ensure availability of its point-of-sale systems. The IT administrator has been asked to improve both server-data fault tolerance and site availability under high consumer load. Which of the following are the BEST options to accomplish this objective'?
(Select TWO)
Load balancing
Incremental backups
UPS
RAID
Dual power supply
In the middle of a cybersecurity, a security engineer removes the infected devices from the network and lock down all compromised accounts. In which of the following incident response phases is the security engineer currently operating?
Identification
Preparation
Eradiction
Recovery
Containment
An analyst visits an internet forum looking for information about a tool. The analyst finds a threat
that appears to contain relevant information. One of the posts says the following:
Hello everyone,
I am having the same problem with my server. Can you help me?
<script type="text/javascript" src=http://website.com/user.js>
Onload=aqlexec();
</script>
Thank you,
Joe
Which of the following BEST describes the attack that was attempted against the forum readers?
SOU attack
DLL attack
XSS attack
API attack
Which of the following organizational policies are MOST likely to detect fraud that is being conducted by existing employees?
(Select TWO).
Offboarding
Mandatory vacation
Job rotation
Background checks
Separation of duties
When selecting a technical solution for identity management, an architect chooses to go from an in-house to a third-party SaaS provider. Which of the following risk management strategies is this an example of?
Acceptance
Mitigation
Avoidance
Transference
A security analyst is looking for a solution to help communicate to the leadership team the seventy levels of the organization's vulnerabilities. Which of the following would BEST meet this need?
CVE
SIEM
SOAR
CVSS
