NEW
Font size
WorksheetsQUIZ #1 SECURITY+
Total questions: 10
Worksheet time: 20mins
You receive an email with a screenshot showing a command prompt at one
of your application servers. The email suggests you engage the hacker for
a day's consultancy to patch the vulnerability. How should you categorize
this threat?
Black hat Activities
Corrective threat
Qualitative threat
Grey hat Activities
What term is used to describe the property of a secure network where a
sender cannot deny having sent a message?
Confidentiality
WSA
Accounting
Non-repudation
Which of the following would be assessed by likelihood and impact:
¿vulnerability, threat, or risk?
Vulnerability
Threat
Risk
What are the properties of a secure information processing system?
Security Controls
Confidentiality, Integrity and Availability
Firewalls, IDS, ETC
Security,
Awareness,
Apliances
You have implemented a secure web gateway that blocks access to a social
networking site. How would you categorize this type of security control?
Physical
Corrective
Technical
Deterrent
A firewall appliance intercepts a packet that violates policy. It automatically
updates its Access Control List to block all further packets from the source
IP. What two functions is the security control performing?
Preventive and Corrective
Deterrent and Corrective
Compensating and Preventive
Deterrent and Detective
If a company wants to ensure it is following best practice in choosing
security controls, what type of resource would provide guidance?
Assessments /
Tests
Security Policy
Threat Intelligence
Frameworks/
Benchmarks
A company has installed motion-activated floodlighting on the grounds
around its premises. What class is this security control?
Compensative
Physical
Detective
True or false? Nation state actors primarily only pose a risk to other states.
True
False
A multinational company manages a large amount of valuable intellectual
property (IP) data, plus personal data for its customers and account holders.
What type of business unit can be used to manage such important and
complex security requirements?
CISO
SOC2
SOC
SOC3
