wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CÂU HỎI TRONG SLIDES CỦA THẦY

Total questions: 16

Worksheet time: 8mins

Name
Class
Date
1.

The Chief information security officer _CISO wants to improve the organization’s ability to manage and prevent malware infections. Some of her goals are to(1) detect, record, evaluate, and respond to suspucious activities and events, which may be coused by problematic software or by vaid and invaid users,(2) collect event infor ankd report it to a central ML analysis angine, and (3) detect abuses that are potentially more advanced than what can be detected by traditional antivirus or HIDSs. The solution needs to be able to reduce response and remediation time, reduce false positives, and manage multiple threats simultaneously. What solution is the CISO wanting to implement?


a)

NGFW


b)

WAF


c)

XSRF


d)

EDR 


2.

Your organization is planning on building a new primary headquarters in a new town. You have been asked to contribute to the design process, so you have been give copies of the proposed blueprints to review. Which of the following is not a security-focused design element of a facility or site?


a)

Separation of work and visitor 


b)

Restricted access to areas with higher value or importance


c)

Confidential assets located in the heart or center of a facility


d)

Equal access to all locations within a facility


3.

An attacker was able to gain access to an organization’s perimeter firewall and made changes to allow wider external access and to steal data. Which of the following would have BEST provided timely identification of this incident?


a)

Implementing a data loss prevention (DLP) suite 


b)

Deploying an intrusion prevention system(IPS)


c)

Deploying a security information and event management system (SIEM)


d)

Conducting regular system administration awareness training


4.

When monitoring the security of a web-based application, which of the following is MOST frequently reviewed?


a)

Threat metrics


b)

Audit reports


c)

Access logs

d)

Access lists


5.


______includes a list of responsibilities people who will perform the steps for recovery, inventory for the hardware and software, and steps to recover from a disaster.


a)

Mitigation


b)

Transference


c)

Disaster Recovery Plan


d)

Response strategy 


6.

The risk formual is Risk = Likelihood x Impact


a)

True

b)
  1. False

7.

which of the following is commonly used in a distributed denial of service (DDoS) attack?


a)
  1. Phishing

b)
  1. Adware

c)
  1. Botnet

d)
  1. Trojan

8.

James is the administrator for his organization’s symmetric key cryptography system. He issue keys to users when the need arises. Mary and Beth recently approached him and presented a need to be able to exchange encrypted files securely .How many key must James generate? 


a)

one


b)

two

c)

three

d)

four

9.

After completing an incident response process and providing a final report to management, what step should Casey use to identify improvement to her incident response plan?


a)
  1. Update systems documentation

b)
  1. Conduct a lessons- learned session

c)
  1. Review patching status and vulnerability scans

d)
  1. Engage third- party consultants

10.

When selecting and implementing information asset protection standards, the process of scoping refers to which of the following?


a)
  1. Choosing the standard that most closely provides for regulatory compliance within your organization’s industry

b)
  1. Altering provisions of the chosen standard so that they are more relevant to your your organization’s environment 

c)
  1. Making decisions with respect to internal penalties for noncompliance with the chosen standard

d)
  1. Eliminating from implementation the parts of the chosen standard that are not relevant to your organization’s environment.

11.

After completing a risk assessment, an organization was able to reduce the risk through the addition of detective and preventive controls. However, these controls dis not remove all risk. What options does the organization have for treating the remaining risk?


a)
  1. Accept, avoid, reduce, or transfer

b)
  1. None- the organization must accept the risk

c)
  1. the organization must be either accept or transfer the risk

d)
  1. Does not apply: remaining risk cannot be treated further

12.

What is the different between a virus and a worm?


a)
  1. A virus can infect the boot  sector but a worm cannot

b)
  1. A worm spreads by itself but a virus must attach to an e-mail.

c)
  1. A worm spreads by itself but a virus must attach to another program.

d)
  1. A virus is written in C++ but a worm is written in shell code.

13.

Which of the following defines risk management?


a)

A Understands how security measure are implemented in your environment 


b)

B Gives an idea threats your system is exposed to 


c)

C. Can increase the occurrence of negative events


d)

D. Calculates the risk


14.

Which of the following organizational documentation provide high level objectives that change infrequently?


a)

Standards

b)

Policy


c)

Procedures


d)

Guideline


15.

What is the best countermeasure against social engineering?


a)

User awareness training

b)

Strong passwords

c)
  1. Acceptable use policy

d)
  1. Access auditing

16.

Which of the following is a true statement about ARP poisoning or MAC spoofing?

a)

MAC spoofing is used to overload the memory of a switch


b)

ARP poisoning is used to falsify the physical address of a system to impersonate that of another authorized device


c)

ARP poisoning can use unsolicited or gratuitous replies


d)

MAC spoofing relies on ICMP communication to traverse routers.