WorksheetsBlue Team Assesment
Total questions: 17
Worksheet time: 17mins
Why are log files important for an organization to detect and investigate cyber incidents?
For performance monitoring
For backups
To detect and respond to security incidents
To archive the organization's history
Which files contains user's password hashes on Linux?
/var/log/auth.log
/etc/passwd
/etc/shadow
iptables.log
What is the function of a firewall?
Cleans malware
Monitors and controls network traffic
Speeds up data transfer between computers
Provides email security
What does an "Intrusion Detection System (IDS)" monitor to prevent unauthorized access to a network?
Network traffic and detects attacks
finds missing patches
Encrypts email messages
Implements system updates
Why is incident response important in cybersecurity?
For training purposes
To update web browsers
To respond quickly to cyberattacks
To increase network speed
What does network security monitoring help organizations track?
System performance
User activities
Log data
Weather conditions
What type of application attack is SQL injection an example of?
DoS attack
Ransomware attack
XSS (Cross-Site Scripting) attack
Database security attack
IPS stands for (a)
Which one is connection oriented protocol?
TCP
UDP
DNS is a OSI layer 4 protocol. T/F
True
False
Type a few Web Application Attacks that you know..
Type some OSINT tool names that you know.
Which one is a web protocol?
SSH
TELNET
DNS
HTTP
If you've installed Anti-Virus solution you're safe.(T/F)
True
False
Regarding the picture, can you trust this e-mail? and why?
Let's say you've received an alert containing the following URL.
http:/website.com/displayPicture?filenamE=../../../../etc/passwd
Which of the following BEST describes the attack?
SQL injection
Cross Site Scripting
Directory Traversal
DDoS Attack
Which protol map domain names to IP address?
ARP
SMTP
DNS
HTTP
