WorksheetsCÂU HỎI TRONG SLIDES CỦA THẦY
Total questions: 16
Worksheet time: 8mins
The Chief information security officer _CISO wants to improve the organization’s ability to manage and prevent malware infections. Some of her goals are to(1) detect, record, evaluate, and respond to suspucious activities and events, which may be coused by problematic software or by vaid and invaid users,(2) collect event infor ankd report it to a central ML analysis angine, and (3) detect abuses that are potentially more advanced than what can be detected by traditional antivirus or HIDSs. The solution needs to be able to reduce response and remediation time, reduce false positives, and manage multiple threats simultaneously. What solution is the CISO wanting to implement?
NGFW
WAF
XSRF
EDR
Your organization is planning on building a new primary headquarters in a new town. You have been asked to contribute to the design process, so you have been give copies of the proposed blueprints to review. Which of the following is not a security-focused design element of a facility or site?
Separation of work and visitor
Restricted access to areas with higher value or importance
Confidential assets located in the heart or center of a facility
Equal access to all locations within a facility
An attacker was able to gain access to an organization’s perimeter firewall and made changes to allow wider external access and to steal data. Which of the following would have BEST provided timely identification of this incident?
Implementing a data loss prevention (DLP) suite
Deploying an intrusion prevention system(IPS)
Deploying a security information and event management system (SIEM)
Conducting regular system administration awareness training
When monitoring the security of a web-based application, which of the following is MOST frequently reviewed?
Threat metrics
Audit reports
Access logs
Access lists
______includes a list of responsibilities people who will perform the steps for recovery, inventory for the hardware and software, and steps to recover from a disaster.
Mitigation
Transference
Disaster Recovery Plan
Response strategy
The risk formual is Risk = Likelihood x Impact
True
False
which of the following is commonly used in a distributed denial of service (DDoS) attack?
Phishing
Adware
Botnet
Trojan
James is the administrator for his organization’s symmetric key cryptography system. He issue keys to users when the need arises. Mary and Beth recently approached him and presented a need to be able to exchange encrypted files securely .How many key must James generate?
one
two
three
four
After completing an incident response process and providing a final report to management, what step should Casey use to identify improvement to her incident response plan?
Update systems documentation
Conduct a lessons- learned session
Review patching status and vulnerability scans
Engage third- party consultants
When selecting and implementing information asset protection standards, the process of scoping refers to which of the following?
Choosing the standard that most closely provides for regulatory compliance within your organization’s industry
Altering provisions of the chosen standard so that they are more relevant to your your organization’s environment
Making decisions with respect to internal penalties for noncompliance with the chosen standard
Eliminating from implementation the parts of the chosen standard that are not relevant to your organization’s environment.
After completing a risk assessment, an organization was able to reduce the risk through the addition of detective and preventive controls. However, these controls dis not remove all risk. What options does the organization have for treating the remaining risk?
Accept, avoid, reduce, or transfer
None- the organization must accept the risk
the organization must be either accept or transfer the risk
Does not apply: remaining risk cannot be treated further
What is the different between a virus and a worm?
A virus can infect the boot sector but a worm cannot
A worm spreads by itself but a virus must attach to an e-mail.
A worm spreads by itself but a virus must attach to another program.
A virus is written in C++ but a worm is written in shell code.
Which of the following defines risk management?
A Understands how security measure are implemented in your environment
B Gives an idea threats your system is exposed to
C. Can increase the occurrence of negative events
D. Calculates the risk
Which of the following organizational documentation provide high level objectives that change infrequently?
Standards
Policy
Procedures
Guideline
What is the best countermeasure against social engineering?
User awareness training
Strong passwords
Acceptable use policy
Access auditing
Which of the following is a true statement about ARP poisoning or MAC spoofing?
MAC spoofing is used to overload the memory of a switch
ARP poisoning is used to falsify the physical address of a system to impersonate that of another authorized device
ARP poisoning can use unsolicited or gratuitous replies
MAC spoofing relies on ICMP communication to traverse routers.
