wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Security + quiz 14

Total questions: 14

Worksheet time: 8mins

Name
Class
Date
1.

A nuclear plant was the victim of a recent attack, and all the networks were air gapped. A subsequent investigation revealed a worm as the source of the issue. Which of the following BEST explains what happened?

a)

A malicious USB was introduced by an unsuspecting employee.

b)

The ICS firmware was outdated

c)

A local machine has a RAT installed.

d)

The HVAC was connected to the maintenance vendor.

2.

Under GDPR, which of the following is MOST responsible for the protection of privacy and website user rights?

a)

The data protection officer

b)

The data processor

c)

The data owner

d)

The data controller

3.

A user recent an SMS on a mobile phone that asked for bank delays. Which of the following social-engineering techniques was used in this case?

a)

SPIM

b)

Vishing

c)

Spear phishing

d)

Smishing

4.

A security administrator needs to create a RAIS configuration that is focused on high read speeds and fault tolerance. It is unlikely that multiple drivers will fail simultaneously. Which of the following RAID configurations should the administration use?

a)

RA1D 0

b)

RAID1

c)

RAID 5

d)

RAID 10

5.

A user is concerned that a web application will not be able to handle unexpected or random input without crashing. Which of the following BEST describes the type of testing the user should perform?

a)

Code signing

b)

Fuzzing

c)

Manual code review

d)

Dynamic code analysis

6.

A security administrator checks the table of a network switch, which shows the following output:

VLAN Physical Address Type Port

1 001a:42ff:5113 Dynamic GEO/5

1 0faa:abcf:ddee Dynamic GEO/5

1 c6a9:6b16:750e Dynamic GEO/5

1 a3aa:b6a3:1212 Dynamic GEO/5

1 8025:2ad8:bfac Dynamic GEO/5

1 b839:f995:a00a Dynamic GEO/5

Which of the following is happening to this switch?

a)

MAC Flooding

b)

DNS poisoning

c)

MAC cloning

d)

ARP poisoning

7.

A company needs to centralize its logs to create a baseline and have visibility on its security events. Which of the following technologies will accomplish this objective?

a)

Security information and event management

b)

A web application firewall

c)

A vulnerability scanner

d)

A next-generation firewall

8.

The SOC is reviewing process and procedures after a recent incident. The review indicates it took more than 30 minutes to determine that quarantining an infected host was the best course of action. The allowed the malware to spread to additional hosts before it was contained. Which of the following would be BEST to improve the incident response process?

a)

Updating the playbooks with better decision points

b)

Dividing the network into trusted and untrusted zones

c)

Providing additional end-user training on acceptable use

d)

Implementing manual quarantining of infected hosts

9.

An organization has been experiencing outages during holiday sales and needs to ensure availability of its point-of-sale systems. The IT administrator has been asked to improve both server-data fault tolerance and site availability under high consumer load. Which of the following are the BEST options to accomplish this objective'?

(Select TWO)

a)

Load balancing

b)

Incremental backups

c)

UPS

d)

RAID

e)

Dual power supply

10.

In the middle of a cybersecurity, a security engineer removes the infected devices from the network and lock down all compromised accounts. In which of the following incident response phases is the security engineer currently operating?

a)

Identification

b)

Preparation

c)

Eradiction

d)

Recovery

e)

Containment

11.

An analyst visits an internet forum looking for information about a tool. The analyst finds a threat

that appears to contain relevant information. One of the posts says the following:

Hello everyone,

I am having the same problem with my server. Can you help me?

<script type="text/javascript" src=http://website.com/user.js>

Onload=aqlexec();

</script>

Thank you,

Joe

Which of the following BEST describes the attack that was attempted against the forum readers?

a)

SOU attack

b)

DLL attack

c)

XSS attack

d)

API attack

12.

Which of the following organizational policies are MOST likely to detect fraud that is being conducted by existing employees?

(Select TWO).

a)

Offboarding

b)

Mandatory vacation

c)

Job rotation

d)

Background checks

e)

Separation of duties

13.

When selecting a technical solution for identity management, an architect chooses to go from an in-house to a third-party SaaS provider. Which of the following risk management strategies is this an example of?

a)

Acceptance

b)

Mitigation

c)

Avoidance

d)

Transference

14.

A security analyst is looking for a solution to help communicate to the leadership team the seventy levels of the organization's vulnerabilities. Which of the following would BEST meet this need?

a)

CVE

b)

SIEM

c)

SOAR

d)

CVSS