WorksheetsHàng nóng
Total questions: 101
Worksheet time: 51mins
When a company hires an insurance company to mitigate risk, which risk management technique is being applied?
A. Risk mitigation
B. Risk avoidance
C. Risk tolerance
D. Risk transfer
In the context of risk management, which information does ALE outline?
A. The business impact of a risk
B. The percentage of Asset Lost Efficiency
C. The expected cost per year of not performing a given risk-mitigating action
D. The probability of a risk coming to pass in a given year
On an Incident Response team, which role acts as the team's main link to Senior Management?
A. Information security
B. Management
C. Communications and public relations
D. Technical Expert
(*) Which of these statements about the security implications of IPv6 is NOT true?
A. IPv6 reputation services may not be mature and useful
B. IPv6 traffic may bypass existing security controls
C. IPv6's NAT implementation is insecure
D. Rules based on static IPv6 addresses may not work
(*) Which of these different sub-masks will allow 30 hosts?
A. /27
B. /26
C. /29
D. /30
Which of these is NOT a typical component of a comprehensive business continuity plan (BCP)?
A. Notification systems and call trees for alerting personnel
B. Immediate response procedures and checklists
C. A list of the BCP team members
D. A cost prediction of the immediate response procedures
Which of these terms refers to threats with unusually high technical and operational sophistication, spanning months or even years?
A. Rootkit
B. Side-channel
C. APT
D. Ping of death
Which of these pairs does NOT constitute Multi-Factor Authentication (MFA)?
A. PIN and credit card.
B. Username and retina scan.
C. Password and username.
D. Fingerprint and Password.
Which type of attack PRIMARILY aims to consume all the available resources, thereby making an organization's service inaccessible to its intended users?
A. Cross-Site Scripting
B. Trojans
C. Denial of Service
D. Phishing
Which of these is NOT a feature of a SIEM (Security Information and Event Management)?
A. Log retention
B. Log auditing
C. Log encryption
D. Log consolidation
Which of these is not an attack against an IP network?
A. Man-in-the-middle Attack
B. Fragmented Packet Attack
C. Side-channel Attack
D. Oversized Packet Attack
As an (ISC)?2 member, you are expected to perform with due care. What does ‘due care’ specifically mean?
A. Give continuity to the legacy of security practices of your company
B. Researching and acquiring the knowledge to do your job right
C. Do what is right in each situation you encounter on the job
D. Apply patches annually
Which of these is NOT one of the (ISC)2 ethics canons?
A. Act honorably, honestly, justly, responsibly, and legally
B. Protect society, the common good, necessary public trust and confidence, and the infrastructure
C. Provide diligent and competent service to principals
D. Consider the social consequences of the systems you are designing
(*) What technology is MOST LIKELY to conserve the storage space required for video recordings?
A. PTZ
B. Motion detection
C. Facial recognition
D. Infrared cameras
Which of these exercises goes through a sample of an incident step-by-step, validating what each person will do?
A. A walk-through exercise
B. A checklist exercise
C. A tabletop exercise
D. A simulation exercise
The name, age, location and job title of a person are all examples of:
A. Attributes
B. Biometric factors
C. Account permissions
D. Identity factors
What is the PRIMARY objective of a rollback in the context of the change management process?
A. Restore the system to its last state before the change was made
B. Validate the system change process
C. Establish a minimum understood and acceptable level of security requirements
D. Identify the required changes needed
Which of these techniques will ensure the property of 'non-repudiation'?
A. Passwords
B. Encryption
C. Using a VPN
D. Digital signatures
Which of these social engineering attacks sends emails that target specific individuals?
A. Vishing
B. Pharming
C. Spear phishing
D. Whaling
Which of these is a type of detective access control?
A. Firewalls
B. Bollards
C. Movement Sensors
D. Turnstiles
An Access Control List (ACL) that determines which permissions you have is:
A. The subject
B. The rule
C. The firmware
D. The object
At which of the OSI layers do TCP and UDP work?
A. Physical Layer
B. Application Layer
C. Transport Layer
D. Session Layer
Which of these is an example of a privacy breach?
A. Any observable occurrence in a network or system
B. Access of private information by an unauthorized person
C. Being exposed to the possibility of attack
D. Unavailability of critical systems
During the investigation of an incident, which security policies are more likely to cause difficulties?
A. Configuration standards
B. Incident response policies
C. Communication policies
D. Retention policies
What is the primary goal of a Change Management Policy?
A. To guarantee that system changes are performed without negatively affecting business operations
B. To standardize the creation of the organization's network and computer systems
C. To standardize the usage of the organization's network and computer systems
D. To guarantee that systems are up to date with the latest security patch
The PRIMARY objective of a business continuity plan is:
A. To assess the impact of disruption to the business
B. To sustain business operations while recovering from a disruption
C. To restore the business to the full last-known reliable state of operations
D. To regularly verify whether the organization complies with applicable regulations
In the event of non-compliance, which of these can have considerable financial consequences for an organization?
A. Regulations
B. Standards
C. Guidelines
D. Policies
Which of these documents is MORE directly related to what can be done with a system or with its information?
A. MOA
B. MOU
C. SLA
D. ROE
Which of these enables point-to-point online communication over an untrusted
A. Router
B. VPN
C. Firewall
D. VLAN
(*) A USB pen with data passed around the office is an example of:
A. Data in use
B. Data in motion
C. Data in transit
D. Data at rest
Which of these is included in an SLA document?
A. Instructions on data ownership and destruction
B. A plan to prepare the organization for the continuation of critical business functions
C. Instructions to detect, respond to, and limit the consequences of a cyber-attack
D. A plan to keep business operations going while recovering from a significant disruption
An organization needs a network security tool that detects and acts in the event of malicious activity. Which of these tools will BEST meet their needs?
A. Firewall
B. Router
C. IDS
D. IPS
Which of these types of layers is NOT part of the TCP/IP model?
A. Internet
B. Physical
C. Application
D. Transport
(*) When analyzing risks, which of these activities is required?
A. Accepting all evaluated risks
B. Selecting the appropriate controls
C. Identifying risks associated with loss of confidentiality
D. Determining the likelihood of occurrence of a set of risks
A backup that captures the changes made since the latest full backup is an example of:
A. A backup snapshot
B. A full backup
C. A differential backup
D. An incremental backup
Which of these is an attack whose PRIMARY goal is to gain access to a target system through falsified identity?
A. Ransomware
B. Amplification
C. Spoofing
D. DDoS
A poster reminding the best password management practices is an example of which type of learning activity?
A. Education
B. Schooling
C. Training
D. Awareness
A high-level executive of an organization receives a malicious email that tries to trick him. Which attack is the perpetrator using?
A. DDOS
B. Phishing
C. Spear phishing
D. Whaling
Which of these addresses is commonly reserved specifically for broadcasting?
A. 192.299.121.254
B. 192.299.121.0
C. 192.299.121.255
D. 192.299.121.14
Which of these terms refers to a collection of fixes?
A. Patch
B. Service Pack
C. Hotfix
D. Downgrade
Which of these entities is responsible for signing an organization's policies?
A. Human Resources
B. Financial Department
C. Security engineer
D. Senior management
In a DAC policy scenario, which of these tasks can only be performed by a subject granted access to information?
A. Modifying the information
B. Changing security attributes
C. Executing the information
D. Reading the information
(*) Which of these types of documents is usually THE LEAST formal?
A. Regulations
B. Guidelines
C. Standards
D. Policies
(*) The best defense method to stop a 'Replay Attack’ is to:
A. Use an IPSec VPN
B. Use a Firewall
C. Use message digesting
D. Use password authentication
What does redundancy mean in the context of cybersecurity?
A. Designing systems with robust components, so that the organization has more attack resilience
B. Conceiving systems with duplicate components so that, if a failure occurs, there will be a backup
C. Conceiving systems with only the most necessary components, so that the organization has just the necessary risks.
D. Conceiving systems with less attack surface, so that the attacker has less chance of success
What does the term ‘data remanence’ refer?
A. Data in use that can't be encrypted
B. Files saved locally that can't be remoted accessed
C. Data left over after routine removal and deletion
D. All of the data in a system
(*) Which of these is an example of a MAC address?
A. 2001 : db8: 3333 : 4444 : 5555 : 6666: 7777 : 8888
B. 0051021f58
C. 10.23.19.49
D. 00-51-02-1F-58-F6
Which of these attacks take advantage of inadequate input validation in websites?
A. Cross-Site Scripting
B. Rootkits
C. Trojans
D. Phishing
A security consultant hired to design the security policies for the PHI within an organization will be primarily handling:
A. Personal Health information
B. Protected Health information
C. Procedural Health information
D. Public Health information
Which port number corresponds to the Simple Mail Transfer Protocol (SMTP)?
A. 69
B. 25
C. 22
D.161
What does the term LAN refer to?
A. A device that connects multiple other devices in a network
B. A network on a building or limited geographical area
C. A tool to manage and control network traffic, as well as to protect a network.
D. A long-distance connection between geographically-distant networks
Which one of these tools is MOST likely to detect an XSS vulnerability?
A. Web application vulnerability scanner
B. Static application test
C. Network vulnerability scanner
D. Intrusion detection system
Which of these is a type of corrective security control?
A. Patches
B. Guidelines
C. Encryption
D. Intrusion detection systems
(*) Which is the PRIMARY focus of the ISO 27002 standard?
A. Health Insurance Portability and Accountability Act (HIPAA)
B. Information Security Management System (ISMS)
C. Risk Management
D. Application Security
When a company collects PII, which policy is required?
A. Privacy Policy
B. GDPR
C. Acceptable Use Policy
D. Remote Access Policy
Which of these is NOT a characteristic of the cloud?
A. Zero Customer Responsibility
B. Measured Service
C. Broad Network Access
D. Rapid Elasticity
(*) In the event of a disaster, what should be the PRIMARY objective?
A. Guarantee the safety of people
B. Protect the production database
C. Guarantee the continuity of critical systems
D. Apply disaster communication
Which of these is a COMMON mistake made when implementing record retention policies?
A. Applying shorter retention periods to the information
B. Not categorizing the type of information to be retained
C. Applying the longest retention periods to the information
D. Not labeling the type of information to be retained
(*) Which of these properties is NOT guaranteed by a Message Authentication Code (MAC)?
A. Authenticity
B. Non-repudiation
C. Integrity
D. Anonymity
Which of these is NOT a type of malware?
A. Trojan
B. Rootkit
C. Spoofing
D. Worm
In an incident response process, which phase uses indicators of compromise and log analysis as part of a review of events?
A. Containment
B. Identification
C. Preparation
D. Eradication
Requiring a specific user role to access resources is an example of:
A. DAC
B. ABAC
C. MAC
D. RBAC
Which of these types of malware self-replicates without the need for human intervention?
A. Worm
B. Virus
C. Trojan
D. Rootkits
Which of these is NOT a characteristic of an MSP implementation?
A. Manage all- in-house IT infrastructure
B. Monitor and respond to security incidents
C. Utilize expertise for the implementation of a product or service
D. Mediate, execute and decide top-level decisions
(*) Which of these is the PRIMARY objective of the PCI-DSS standard?
A. Personally Identifiable Information (PII)
B. Change Management
C. Secure Credit Cards Payments
D. Protected Health Information (PHI)
Which of these is LEAST likely to be installed by an infection?
A. Backdoor
B. Trojan
C. Logic Bomb
D. Keylogger
Which department in a company Is NOT typically involved in a Disaster Recovery Plan (DRP)?
A. IT
B. Public Relations
C. Executive
D. Financial
An organization that uses a layered approach when designing its security architecture is using which of these security approaches?
A. Network Control Access
B. Zero trust
C. Network Layers
D. Defense in depth
The PRIMARY objective of a security baseline is to establish ...
. .. a Minimum understood and acceptable level of security requirements
. a maximum understood and an acceptable level of security requirements
. .. security and configuration requirements
... a minimum understood and a good level of security requirements
Which type of security control does NOT include CCTV cameras?
A. Deterrent
B. Detective
C. Corrective
D. Preventive
Acting ethically is mandatory for (ISC)2 members. Which of these is NOT considered unethical?
A. Having fake social media profiles and accounts
B. Seeking to gain unauthorized access to resources on thae internet
C. Disrupting the intended use of the internet
D. Compromising the privacy of users
Which of these cannot be a corrective access control?
A. Patches
B. Backups
C. Bollards
D. CCTV cameras
Which of these Access Control Systems is commonly used in the military?
A. RBAC
B. DAC
C. ABAC
D. MAC
What is the PRIMARY objective of a degaussing?
A. Reducing noisy data on a disk
B. Preventing magnetic side-channel attacks
C. Retaining the data on a disk
D. Erasing the data on a disk
Which of these is not a common goal of a cybersecurity attacker?
A. Allocation
B. Alteration
C. Denial
D. Disclosure
Which of these is NOT a security principle?
A. Zero Trust model
B. Separation of Duties
C. Least Privilege
D. Security in Depth (SID)
Which cloud service model provides the most suitable environment for customers who want to install their custom operating system?
A. laaS
B. SLA
C. SaaS
D. PaaS
When looking for cybersecurity insurance, which of these is the MOST IMPORTANT objective?
A. Risk transference
B. Risk spreading
C. Risk avoidance
D. Risk acceptance
A security professional should report violations of a company's security policy to:
A. Company management
B. The ISC Ethics Committee
C. National authorities
D. A court of law
(*) Which of these statements is TRUE about cybersquatting?
A. It is an illegal practice
B. It is s a legal practice
C. Its an unethical practice but everyone does it
D. It is partially illegal practice
Which kind of document outlines the procedures ensuring that vital company systems keep running during business-disrupting events?
A. Business Impact Plan
B. Business Continuity Plan
C. Business Impact Analysis
D. Disaster Recovery Plan
While performing background checks on new employees, which of these can NEVER be an attribute for discrimination?
A. References, education, political affiliation, employment history
B. Credit history, employment history, references
C. Criminal Records, credit history, references
D. Employment history, references, criminal records
Which of these technologies is the LEAST effective means of preventing shared accounts?
A. Password complexity requirements
B. Requiring a one-time password via an application
C. Requiring biometric authentication
D. Requiring one-time passwords via a token
Which of these is an attack that encrypts the organization's information, and then demands payment for the decryption code?
A. DDoS
B. Spoofing
C. Ransomware
D. Phishing
Which of these is NOT a best practice in access management?
A. Giving only the right amount of permission
B. Periodically assessing whether user permissions still apply
C. Requesting a justification when upgrading permission
D. Trust but Verify
Which of these devices has the PRIMARILY objective of determining the most efficient path for the traffic to flow across the networks?
A. Hubs
B. Switches
C. Firewalls
D. Routers
Which method is COMMONLY used to map live hosts in the network?
A. Wireshark
B. Ping sweep
C. Geolocation
D. Traceroute
Which type of attack attempts to mislead the user into exposing personal information by sending fraudulent emails?
A. Denial of Service
B. Trojans
C. Phishing
D. Cross-Site Scripting
Which part of the CIA Triad will be PRIMARILY jeopardized in a Distributed Denial Of Service (DDOS) attack?
A. Integrity
B. Availability
C. Confidentiality
D. Accountability
When an incident occurs, which of these is not a PRIMARY responsibility of an organization's response team?
A. Determining whether any confidential information has been compromised over the course of the entire incident
B. Implementing the recovery procedures necessary to restore security and recover from any incidentrelated damage
C. Communicating with top management regarding the circumstances of the cybersecurity event
D. Determining the scope of the damage caused by the incident
(*) Which type of recovery site has some or most systems in place, but does not have the data needed to take over operations?
A. A cold site
B. A cloud site
C. A hot site
D. A warm site
Which of these is NOT an effective way to protect an organization from cybercriminals?
A. Using firewalls
B. Removing or disabling unneeded services and protocols
C. Using up-to-date anti-malware software
D. Using intrusion detection and prevention systems
Which of these is part of the canons (ISC)?2 code of ethics?
A. Advance and protect the profession
B. Provide diligent and competent services to stakeholders
C. Act always in the best interest of your client
D. Prevent and detect unauthorized use of digital assets in a society
(*) Which of these is NOT a best practice in access management?
A. Periodically assessing whether user permissions still apply
B. Giving only the right amount of permission
C. Trust but verify
D. Requesting a justification when upgrading permission
Which kind of physical access control is LESS effective at preventing unauthorized individual access to a data center?
A. Bollards
B. Turnstiles
C. Barriers
D. Fences
Which of these types of credentials is NOT used in multi-factor authentication?
A. Something you are
B. Something you have
C. Something you trust
D. Something you know
On a BYOD model, which of these technologies is best suited to keep corporate data and applications separate from personal?
A. Full-device encryption
B. Containerization
C. Context-aware authentication
D. Biometrics
What is the most important difference between MAC and DAC?
A. In MAC, security administrators set the roles for the users; in DAC, roles are set at the object owner's discretion
B. In MAC, security administrators assign access permissions; in DAC, security administrators set user roles
C. In MAC, access permissions are set at the object owner's discretion; in DAC, it is up to security administrators to assign access permissions
D. In MAC, security administrators assign access permissions; in DAC, access permissions are set at the object owner's discretion
Which of these techniques is PRIMARILY used to ensure data integrity?
A. Backups
B. Hashing
C. Content Encryption
D. Message Digest
Which of these cloud deployment models is a combination of public and private cloud storage?
A. Community
B. Public
C. Private
D. Hybrid
Suppose that an organization wants to implement measures to strengthen its detective access controls. Which one of these tools should they implement?
A. Backups
B. Patches
C. IDS
D. Encryption
