wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

3 курс Cybersecurity Compliance Framework & System Administratio

Total questions: 55

Worksheet time: 32mins

Name
Class
Date
1.

Which of the bad guys are described as "They are "in" an organization but are human and make mistakes"?

a)

Inadvertant Actor

b)

Malicious Insiders

c)

Outsiders

d)

Employees

2.

Which is NOT one of the security controls?

a)

Physical

b)

Operational

c)

Testing

d)

Technical

3.

What year did the European Union start enforcing GDPR?

a)

2018

b)

2017

c)

2016

d)

2014

4.

Which three (3) of these obligations are part of the 5 key GDPR obligations?

a)

Consent

b)

Security of Public Data

c)

Accountability of Compliance

d)

Rights of EU Data Subject

5.

Which is the foundational principle that everyone will get during a SOC audit?

a)

Privacy

b)

Availability

c)

Security

d)

Confidentiality

6.

The HIPAA security rule requires covered entites to maintain which two (2) reasonable safeguards for protecting e-PHI?

a)

Physical

b)

Technical

c)

Operational

d)

Informational

7.

HIPAA Administrative safeguards include which two (2) of the following?

a)

Security Personnel

b)

Access Controls

c)

Integrity Controls

d)

Workforce Training and Management

8.

PCI includes 264 requirements grouped under how many main requirements?

a)

5

b)

10

c)

12

d)

20

9.

If you are a mature organization which CIS Controls Implementation Group would you use?

a)

Implementation Group 3

b)

Implementation Group 2

c)

Do not need a controls implementation group due to maturity of my organization

d)

Implementation Group 1

10.

A security attack is defined as which of the following?

a)

All cybersecurity events.

b)

An event that has been reviewed by analysts and deemed worthy of deeper investigation.

c)

An event that has been identified by correlation and analytics tools as a malicious activity.

d)

An event on a system or network detected by a device.

11.

Which order does a typical compliance process follow?

a)

Establish scope, readiness assessment, gap remediation, testing/auditing, management reporting

b)

Readiness assessment, establish scope, testing/auditing, management reporting, gap remediation

c)

Readiness assessment, establish scope, gap remediation, testing/auditing, management reporting

d)

Establish scope, readiness assessment, testing/auditing, management reporting, gap remediation

12.

Under GDPR who determines the purpose and means of processing of personal data?

a)

Data Subject

b)

Controller

c)

Processor

d)

Analyst

13.

Under the International Organization for Standardization (ISO) which standard focuses on Privacy?

a)

ISO 27003

b)

ISO 27017

c)

ISO 27018

d)

ISO 27001

14.

Which SOC report is closest to an ISO report?

a)

Type 1 and Type 2

b)

Type 1

c)

Type 2

d)

Type 3

15.

What is an auditor looking for when they test the control for implementation over an entire offering with no gaps?

a)

Completeness

b)

Timeliness

c)

Consistency

d)

Accuracy

16.

The HIPAA Security Rule requires covered entities to maintain which three (3) reasonable safeguards for protecting e-PHI?

a)

physical

b)

administrative

c)

operational

d)

technical

17.

HIPAA Administrative safeguards include which two (2) of the following?

a)

Security Personnel

b)

Integrity controls

c)

Workforce training and management

d)

Access controls

18.

Who is the governing entity for HIPAA?

a)

US Department of Health and Human Services Office of Civil Rights

b)

Cyber Security and Infrastructure Security Agency (CISA)

c)

US Legislature

d)

Department of Homeland Security

19.

HIPAA Physical safeguards include which two (2) of the following?

a)

Information Access Management

b)

Transmission Security

c)

Workstation and Device Security

d)

Facility Access and Control

20.

PCI uses which three (3) of the following Card Holder Data Environment categories to determine scope?

a)

Processes

b)

People

c)

Technology

d)

Governance

21.

One PCI Requirement is using an approved scanning vendor to scan at what frequency?

a)

Weekly

b)

Monthly

c)

Quarterly

d)

Annually

22.

In which CIS control category will you find Incident Response and Management?

a)

Foundational

b)

Organizational

c)

Basic

d)

Advanced

23.

Which is NOT an example of a client?

a)

Personal Computer

b)

Laptop

c)

Cellphone

d)

e-mail Server

24.

Which three (3) threat key factors should be considered when looking at an Endpoint Security Solution?

a)

user education

b)

detection response

c)

threat hunting

d)

basic operations

25.

A patch is a set of changes to a computer program or its data designed for which three (3) functions?

a)

update

b)

fix

c)

delete

d)

improve

26.

Which two types of updates do most organizations patch as soon as possible after testing?

a)

Critical and Software

b)

Security and Critical

c)

Critical and Service Paks

d)

Security and Service Paks

27.

Which three (3) are common Endpoint attack types?

a)

SQL Injection

b)

Spear Phishing

c)

Whale hunting

d)

Ad Network

28.

Endpoint detection and response includes which three (3) of these key technologies?

a)

Zero-day OS updates.

b)

One-Time patching process.

c)

Continuous monitoring.

d)

Automatic policy creation for endpoints.

29.

Which common endpoint attack is targeted at supply chain infiltration?

a)

Water Hole

b)

Island Hopping

c)

Spear Phishing

d)

Ransomware

30.

What two windows security updates do most organizations always patch?

a)

critical and important

b)

critical and high

c)

important and moderate

d)

high and important

31.

How frequent will most organizations distribute patches?

a)

Monthly

b)

Weekly

c)

Annually

d)

As soon as patches are released

32.

Which three (3) objects are typically managed by active directory?

a)

Local Accounts

b)

Services

c)

Volumes

d)

Network User

33.

Which type of group within Active Directory is used to assign permissions to shared resources?

a)

Distribution groups

b)

Data groups

c)

Service groups

d)

Security groups

34.

Kerberos Authentication provides several benefits including which three (3) of the following?

a)

distributed authentication

b)

interoperability

c)

single sign on

d)

delegated authentication

35.

Which of the nine different kinds of Windows events that can be audited is used to see when someone has shutdown or restarted the computer or when a program tries to do something it does not have permission to do?

a)

Process tracking

b)

System events

c)

Privilege Use

d)

Policy change

36.

True or False: Internal commands are built into the shell program and are shell dependent?

a)

True

b)

False

37.

Which Linux Run Level shuts down all services when the system is being rebooted?

a)

Run Level 0: Halt

b)

Run Level 1: Single User

c)

Run Level 5: Graphical

d)

Run Level 6: Reboot

38.

Which Windows directory folder stores per-user application data and settings?

a)

\Users

b)

\Program Files

c)

\AppData

d)

\System

39.

Which is NOT an example of a default Windows local user account?

a)

HelpAssistant

b)

Network Service

c)

Guest

d)

Administrator

40.

Which feature allows Active Directory to be shared by multiple servers?

a)

A global catalog

b)

A query and index mechanism

c)

A replication services

d)

A Set of rules

41.

Which three (3) of the following steps can be taken to help protect sensitive Windows domain accounts? (Select 3)

a)

Disable the account delegation rights for administrator accounts.

b)

Create dedicated workstation hosts without Internet and email access.

c)

Grant user logon access to servers and workstations.

d)

Separate administrator accounts from user accounts.

42.

What tool can an administrator use to manage servers on private networks that are not connected to the Internet?

a)

Privileged Admin Center

b)

Network Admin Center

c)

Windows Admin Center

d)

AWS Active Directory

43.

Which of the nine different kind of Windows events that can be audited is used to see each instance of a user logging on to and logging off from another computer?

a)

Account management

b)

Account logon

c)

Directory service access

d)

Object access

44.

Which of these commands does not shutdown the Linux operating system?

a)

reboot

b)

grep

c)

shutdown -r

d)

init 6

45.

Which Linux commands are totally shell-independent and usually found in any Linux distribution?

a)

External commands

b)

Internal commands

46.

Which three (3) of the following are common choices of Shell?

a)

Bash

b)

tcsh

c)

sh

d)

Lsh

47.

Which of the cryptography basics ensures authentication, non-repudiation and integrity?

a)

Public key encryption

b)

Hashing

c)

Digital Signatures

d)

Symmetric key encryption

48.

Complete the following statement.

Data can be encrypted_____

a)

at rest only.

b)

in use only.

c)

in transit only.

d)

at rest, in use, and in transit.

49.

Which is NOT a pitfall of encryption?

a)

Implementing a reliable and proven cryptography

b)

Using hardcoded/predictable weak keys

c)

Missing encryption of data and communications

d)

Relying on algorithms being secret

50.

True or False: Internal commands are built into the shell program and are shell dependent.

a)

True

b)

False

51.

True or False: A whole branch of hacking - Reverse Engineering - is devoted to discovering hidden algorithms and data.

a)

True

b)

False

52.

Which is not a key takeaway of best practices of cryptography?

a)

Do encrypt all sensitive data, at rest, in use, and in transit.

b)

Do rely on proven algorithms.

c)

Do use hard to guess keys and store them correctly.

d)

Do rely on your own encryption algorithms.

53.

Which three (3) are true of digital signatures?

a)

Uses symmetric key encryption

b)

Ensures authentication, non-reputiation, and integrity

c)

Uses hashing

d)

Uses public key encryption

54.

What is the recommendation to avoid the encrypting data at rest pitfall "Using hardcoded/easily guessed keys"?

a)

Store keys in secure keystores.

b)

Use a new random initialization vectors every time.

c)

Phase them out

d)

Select cryptographically-random keys, do not reuse keys for different installs.

55.

Which two (2) statements are true of the Hash function?

a)

Maps data of arbitrary size to data of a fixed size.

b)

Hashing makes data easy to reconstruct.

c)

Hashing provides integrity.