wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Security Operations Quiz

Total questions: 140

Worksheet time: 1hrs 25mins

Name
Class
Date
1.

The process of applying secure configurations (to reduce the attack surface) and locking down various hardware, communications systems and software.

a)

Harding

b)

Data Handling Model

2.

Its own lifecycle as users create, use, share, and modify it.

a)

Data Handling Model

b)

Harding

3.

Data Handling Model:

"The knowledge, is usually tacit knowledge at this point"

a)

Creating

b)

Storing

c)

Using

d)

Sharing

4.

Data Handling Model:

"Or recording it in some fashion (makes it explicit)"

a)

Storing

b)

Using

c)

Sharing

d)

Archiving

5.

Data Handling Model:

"The knowledge, may cause the information to be modified, supplemented or partially deleted"

a)

Using

b)

Sharing

c)

Archiving

d)

Destorying

6.

Data Handling Model:

"The data with other users, a copy or by moving the data from one location to another

a)

Sharing

b)

Archiving

c)

Destorying

d)

Creating

7.

Data Handling Model:

"The data when it is temporarily not needed"

a)

Archiving

b)

Destorying

c)

Creating

d)

Storing

8.

Data Handling Model:

"The data when it is no longer needed"

a)

Destroying

b)

Creating

c)

Storing

d)

Using

9.

Data Handling Practices:

"Dictate rules and restrictions about how that information can be used, stored and shared with others"

a)

Classification

b)

Labeling

c)

Data Sensitivity Levels and Labels

10.

Data Handling Practices:

"Security labels are part of implementing controls to protect classified information"

a)

Labeling

b)

Data Sensitivity Levels and Labels

c)

Classification

11.

Data Handling Practices:

"Otherwise mandated, organizations are free to create classification systems that best meet their own needs"

a)

Data Sensitivity Levels and Labels

b)

Labeling

c)

Classification

12.

Data Handling Practices:

"Compromise of data with this sensitivity label could possibly put the organization's future existence at risk"

a)

Highly restricted

b)

Moderately restricted

c)

Low sensitivity/Internal Use Only

d)

Unrestricted public data

13.

Data Handling Practices:

"Compromise of data with this sensitivity label could lead to loss of temporary competitive advantaged loss of revenue or disruption of planned investments or activities"

a)

Moderately restricted

b)

Low sensitivity/Internal Use Only

c)

Unrestricted public data

d)

Highly restricted

14.

Data Handling Practices:

"Compromise of data with this sensitivity label could cause minor disruptions, delays or impacts"

a)

Low sensitivity/Internal Use Only

b)

Unrestricted public data

c)

Highly restricted

d)

Moderately restricted

15.

Data Handling Practices:

"As this data is already published, no harm can come from further dissemination or disclosure"

a)

Unrestricted public data

b)

Low sensitivity/Internal Use Only

c)

Moderately restricted

d)

Highly restricted

16.

Data Handling Practices:

"Information and data should be kept only for as long as it is beneficial, no more and no less"

a)

Retention

b)

Destruction

17.

Data Handling Practices:

"Are applicable both for hard copies and for electric data"

a)

Data retention policies

b)

Records retention policies

18.

Data Handling Practices:

"Indicate how long an organization is required to maintain information and assets"

a)

Records retention policies

b)

Data retention policies

19.

Data Handling Practices:

"Data that might be left on media after deleting is known as remanence and may be significant security concern"

a)

Destruction

b)

Retention

20.

*Clearing the device or system

*Purging the device or system

*Physical destruction of the device or system

*In many routine operational environments

a)

Destruction

b)

Retention

21.

The primary form of instrumentation that attempts to capture signals generated by events.

a)

Logging

b)

Logging and Monitoring the Health of the Information Environment

c)

Robust logging

d)

Log reviews

22.

Is essential to identifying inefficient or improperly performing systems, detecting compromises and providing a record of how systems are used

a)

Logging and Monitoring the Health of the Information Environment

b)

Robust logging

c)

Log reviews

d)

Logging

23.

Provide tools to effectively correlate information from diverse systems to fully understand the relationship between one activity and another

a)

Robust logging

b)

Log reviews

c)

Logging

d)

Logging and Monitoring the Health of the Information Environment

24.

An essential function for identifying security incidents, policy violations, fraudulent activities and operational problems near the time of occurrence

a)

Log reviews

b)

Robust logging

c)

Logging and Monitoring the Health of the Information Environment

d)

Logging

25.

Event Logging Best Practices:

"Refers to surveillance and assessment of all inbound communications traffic and access attempts."

Devices and Tools: Firewalls, Gateways, Remote authentication servers, IDS/IPS tools, SIEM solutions, Anti-malware solution.

a)

Ingress Monitoring

b)

Egress Monitoring

26.

Event Logging Best Practices:

"Used to regulate data leaving the organization's IT environment.

Data loss prevention/Data leak protection: Email (content and attachments), Copy to portable media, File Transfer Protocol (FTP), Posting to web pages/websites, Applications/Application programming interfaces (APIs)

a)

Egress Monitoring

b)

Ingress Monitoring

27.

Protects our personal and business transactions

a)

Encryption

b)

Cryptography

28.

Used to protect information by keeping its meaning or content secret and making it unintelligible to someone who does not have a way to decrypt (unlock) that protected information

a)

Cryptography

b)

Encryption

29.

Cryptographic solutions provide a range of services that can help achieve:

a)

Confidentiality

b)

Integrity

30.

A process and discipline used to ensure that the only changes made to a system are those that have been authorized and validated.

a)

Configuration Management

b)

Inventory

c)

Baselines

d)

Updates

31.

Configuration Management:

"Baseline identification of a system and all its components, interfaces and documentation"

a)

i. Identification

b)

ii. Baseline

c)

iii. Change Control

d)

iv. Verification and Audit

32.

Configuration Management:

"A security minimum level of protection that can be used as a reference point"

a)

ii. Baseline

b)

iii. Change Control

c)

iv. Verification and Audit

d)

i. Identification

33.

Configuration Management:

"An update process for requesting changes to a baseline, by means of making changes to one or more components in that baseline."

a)

iii. Change Control

b)

iv. Verification and Audit

c)

ii. Baseline

d)

i. Identification

34.

Configuration Management:

"A regression and validation process, involving testing and analysis, to verify that nothing in the system was broken by a newly applied set of changes"

a)

iv. Verification and Audit

b)

iii. Change Control

c)

ii. Baseline

d)

i. Identification

35.

Configuration Management:

"An audit process can validate that the currently in-use baseline matches the sum total of its initial baseline plus all approved changes applied in sequence."

a)

iv. Verification and Audit

b)

iii. Change Control

c)

ii. Baseline

d)

i. Identification

36.

Is the 1st step in any asset management process.

Example: Catalog or Registry

a)

Inventory

b)

Baselines

c)

Updates

d)

Patches

37.

Is a total inventory of all the system's components, hardware, software, data, administrative controls, documentation and user instructions

a)

Baselines

b)

Updates

c)

Patches

d)

Inventory

38.

Must be acceptance tested to verify that newly installed (or repaired) functionality works as required

a)

Updates

b)

Patches

c)

Baselines

d)

Inventory

39.

The challenge for the security professional is maintaining all patches

a)

Patches

b)

Updates

c)

Baselines

d)

Inventory

40.

Common Security Policies:

"Appropriate use of data"

a)

Data Handling Policy

b)

Password Policy

c)

Acceptable Use Policy (AUP)

d)

Bring Your Own Device (BYOD)

41.

Common Security Policies:

"Every organization should have a password policy in place that defines expectations of systems and users"

a)

Password Policy

b)

Acceptable Use Policy (AUP)

c)

Bring Your Own Device (BYOD)

d)

Privacy Policy

42.

Common Security Policies:

"Defines acceptable use of the organization's network and computer systems and can help protect the organization from legal action"

a)

Acceptable Use Policy (AUP)

b)

Bring Your Own Device (BYOD)

c)

Privacy Policy

d)

Change Management Policy

43.

Common Security Policies:

"An organization may allow workers to acquire equipment of their choosing and use personally owned equipment for business (and personal) use

a)

Bring Your Own Device (BYOD)

b)

Privacy Policy

c)

Change Management Policy

d)

Password Policy

44.

Common Security Policies:

Understand and acknowledge that type of information and are made aware of the legal repercussions of handling such sensitive data"

a)

Privacy Policy

b)

Change Management Policy

c)

Bring Your Own Device (BYOD)

d)

Acceptable Use Policy (AUP)

45.

Common Security Policies:

"The discipline of transitioning from the discipline of transitioning from the current state to a future state"

a)

Change Management Policy

b)

Privacy Policy

c)

Bring Your Own Device (BYOD)

d)

Acceptable Use Policy (AUP)

46.

Change Management Components:

"All of the major change movement practices address a common set of core activities that state with a common set of core activities that start with a request for change"

a)

Documentation

b)

Approval

c)

Rollback

47.

Change Management Components:

"To the proper change authorization process based on risk and organizational practices"

a)

Approval

b)

Rollback

c)

Documentation

48.

Change Management Components:

"Depending upon the nature of the change, a variety of activities may need to be completed"

a)

Rollback

b)

Approval

c)

Documentation

49.

Purpose of (a)   training: is to make sure everyone knows what is expected of them, based on responsibilities and accountabilities, and to find out if there is any carelessness or complacency that may pose a risk to the organization.

50.

Learning activities that organizations use:

"The overall goal of education is to help learners improve their understanding of these ideas and their ability to relate them to their own experiences and apply that learning in useful ways"

a)

Education

b)

Training

c)

Awareness

51.

Learning activities that organizations use:

"Focuses on building proficiency in a specific set of skills or actions"

a)

Training

b)

Awareness

c)

Education

52.

Learning activities that organizations use:

"Activities that attract and engage the learner's attention by acquainting them with aspects of an issue, concern, problem or need"

a)

Awareness

b)

Training

c)

Education

53.

Security Awareness Training Examples:

a)

Fire Safety

b)

Phishing

c)

Social Engineering

d)

Password Protection

54.

Encryption makes (a)  

55.

Transforms plaintext into ciphertext

a)

Encryption

b)

Decryption

c)

Key

56.

The password to the data

a)

Key

b)

Encryption

c)

Decryption

57.

Transforms ciphertext back into plaintext

a)

Decryption

b)

Key

c)

Encryption

58.

1) File encryption

2) Disk encryption

3) Device encryption

a)

Protecting Data at Rest/Stored Data

b)

Protecting Data in Transit/Data that's moving over a network

59.

1) HTTPS (web)

2) Email

3) Mobile applications

4) VPN (network)

a)

Protecting Data in Transit/Data that's moving over a network

b)

Protecting Data at Rest/Stored Data

60.

Symmetric shapes have identical halves

a)

True

b)

False

61.

Symmetric vs. Asymmetric Cryptography:

In (a)   encryption you encrypt and decrypt with the same shared secret key

62.

Symmetric vs. Asymmetric Cryptography:

In (a)   encryption you encrypt and decrypt with different keys from the same pair

63.

Symmetric vs. Asymmetric Cryptography:

Asymmetric algorithms use keypairs where each user gets a __ key and a __ key

(a)  

64.

Symmetric vs. Asymmetric Cryptography:

The (a)   key is freely shared

65.

Symmetric vs. Asymmetric Cryptography:

The (a)   key is kept secret

66.

Symmetric vs. Asymmetric Cryptography:

Encrypt with the public key and decrypt with the (a)   key

67.

Keys used for asymmetric encryption and decryption must be from the same pair!

a)

True

b)

False

68.

Symmetric vs. Asymmetric Cryptography:

Advanced Encryption Standard (AES) is (a)  

69.

Symmetric vs. Asymmetric Cryptography:

RSA algorithm is (a)  

70.

_ Functions: One-way functions that transform a variable length input into a unique, fixed-length output

(a)  

71.

*One-way functions can't be reversed

*The output of a hash function will always be the same length, regardless of the input size

*No two inputs to a hash function should produce the same output

a)

Hash Function Characteristics

b)

Hash Functions May Fail

c)

Message Digest 5 (MD5)

72.

*If they are reversible, or

*If they are not collision-resistant

a)

Hash Functions May Fail

b)

Message Digest 5 (MD5)

c)

Hash Function Characteristics

73.

*Ron Rivest created MD5 in 1991

*MD5 is the fifth in a series of hash functions

*Message digest is another term for hash

*MD5 produces 128-bit hashes

*MD5 is no longer secure

a)

Message Digest 5 (MDS)

b)

Hash Functions May Fail

c)

Hash Function Characteristics

74.

*Produces a 160-bit hash value

*Contains security flaws that render it insecure

a)

SHA-1

b)

SHA-2

c)

SHA-3

75.

*Consists of a family of six hash functions

*Produces output of 224, 256, 384, and 512 bits

*Uses a mathematically similar approach to SHA-1 and MD5

*Secure

a)

SHA-2

b)

SHA-3

c)

SHA-1

76.

*Designed to replace SHA-2

*Uses a completely different hash generation approach than SHA-2

*Produces hashes of user-selected fixed length

*Secure

a)

SHA-3

b)

SHA-2

c)

SHA-1

77.

*Created as an alternative to government-sponsored hash functions

*Produces 128, 160, 256, and 320-bit hashes

*Contains flaws in the 128-bit version

*Insecure

a)

RIPEMD

b)

HMAC

78.

*Hash-Based Message Authentication Code

*Combines symmetric cryptography and hashing

*Provides authentication and integrity

*Create and verify message authentication code by using a secret key in conjunction with a hash function

*Secure

a)

HMAC

b)

RIPEMD

79.

(a)   Functions are used with asymmetric cryptograph for digital signatures and digital certificates

80.

The (a)   lifecycle explains the different stages of data in the cloud.

81.

Data Lifecycle:

The organization (a)   new data, either in the cloud or in an on-premises system

82.

Data Lifecycle:

Data is moved into a (a)   repository for retention and later use

83.

Data Lifecycle:

Define: Data is viewed and/or processed by individuals and systems

(a)  

84.

Data Lifecycle:

Data is (a)   with other employees, customers, and partners

85.

Define: Data is moved from active storage to long-term storage repositories

(a)  

86.

Data Lifecycle:

Data is securely (a)   when no longer needed

87.

Is essential to preventing reconstruction

a)

Data destruction

b)

Data classification policies

88.

Assign information into categories, known as classifications, that determine storage, handling, and access requirements

a)

Data classification policies

b)

Data destruction

89.

*Clearing overwrites sensitive information to frustrate casual analysis

*Purging uses more advanced techniques to frustrate laboratory analysis

*Destroying completely obliterates the media through shredding, pulverization, melting, or burning

a)

Data Sanitization Techniques

b)

Different options to disposal

90.

*Shredding

*Pulping

*Burning

a)

Different options to disposal

b)

Data Sanitization Techniques

91.

Third-party services offer (a)   capabilities

92.

The stages of the lifecycle do not always occur in the same order

a)

True

b)

False

93.

*Sensitivity of information

*Criticality of information

a)

Assign Classifications Based Upon

b)

Classification Levels

94.

Military Classification - Top Secret - Secret - Confidential - Unclassified

Business Classification - Highly Sensitive - Sensitive - Internal - Public

a)

Classification Levels

b)

Assign Classifications Based Upon

95.

Classification guides other security decisions

a)

True

b)

False

96.

When an organization classifies information:

"Identify sensitive information"

a)

Labeling Requirements

b)

Classificaton

97.

Types of information classified by external groups:

"Traceable to a specific person"

a)

Personally Identifiable Information (PII)

b)

Protected Health Information (PHI)

c)

Payment Card Information (PCI)

98.

Types of information classified by external groups:

"Covered by HIPAA"

a)

Protected Health Information (PHI)

b)

Payment Card Information (PCI)

c)

Personally Identifiable Information (PII)

99.

Types of information classified by external groups:

"Covered by PCI DSS"

a)

Payment Card Information (PCI)

b)

Protected Health Information (PHI)

c)

Personally Identifiable Information (PII)

100.

Data Classification:

Securely (a)   of information when no longer needed

101.

Are a crucial tools for security professionals

a)

Logs

b)

Classification

102.

Achieve important objectives:

"Who cause the event?"

Also known as Identity Attribution

Example: A specific person, A computer's IP address, A geographic location

a)

Accountability

b)

Traceability

c)

Auditability

103.

Achieve important objectives:

"Uncover all other related events"

Example: Investigating events

a)

Traceability

b)

Auditability

c)

Accountability

104.

Achieve important objectives:

"Provide clear documentation of the events"

a)

Auditability

b)

Traceability

c)

Accountability

105.

Systems generate far too many (a)   records for manual analysis

106.

Artificial (a)   can help solve security data overload

107.

1) Central, secure collection point for logs

*All systems send log entries directly to the SIEM

2) Source of Artificial Intelligence (AI)

a)

Security Information and Event Management (SIEM)

b)

Artificial Intelligence (AI)

108.

(a)   have access to log entries from across the organization

109.

SIEM:

"Triggers the initial alert"

a)

Intrusion Detection System

b)

Firewall Log

c)

Web Server Log

d)

Database Log

110.

SIEM:

1) Suspicious connection

a)

Firewall Log

b)

Web Server Log

c)

Database Log

d)

Router Log

111.

SIEM:

2) SQL injection attack

a)

Web Server Log

b)

Database Log

c)

Router Log

d)

Firewall Log

112.

SIEM:

3) Large query

a)

Database Log

b)

Router Log

c)

Firewall Log

d)

Web Server Log

113.

SIEM:

4) Large outbound data flow

a)

Router Log

b)

Database Log

c)

Web Server Log

d)

Firewall Log

114.

(a)   provide security professionals with a valuable tool, Correlating Security Event Information

115.

Social (a)   presents serious risks to cybersecurity

116.

Manipulating people into divulging information or performing an action that undermines security

a)

Social Engineering

b)

Authority and Trust

c)

Intimidation

d)

Consensus/Social Proof

117.

*Authority

*Intimidation

*Consensus

*Scarcity

*Urgency

*Familiarity

a)

Social Engineering

b)

Education

118.

Social Engineering:

People defer to authority

a)

Authority

b)

Intimidation

c)

Consensus/Social Proof

d)

Scarcity

119.

Social Engineering:

Scaring people

a)

Intimidation

b)

Consensus/Social Proof

c)

Scarcity

d)

Urgency

120.

Social Engineering:

The herd mentality

Example: Riots

a)

Consensus/Social Proof

b)

Scarcity

c)

Urgency

d)

Familiarity/Liking

121.

Social Engineering:

Getting the last one

Example: Releases a new product

a)

Scarcity

b)

Urgency

c)

Familiarity/Liking

d)

Intimidation

122.

Social Engineering:

Time is running out

a)

Urgency

b)

Familiarity/Liking

c)

Scarcity

d)

Consensus/Social Proof

123.

Social Engineering:

We say yes to people we like

a)

Familiarity/Liking

b)

Urgency

c)

Authority and Trust

d)

Intimidation

124.

Education is the solution

a)

True

b)

False

125.

Impersonation Attacks:

Unsolicited commercial email

a)

Spam

b)

Phishing

c)

Spear Phishing

d)

Whaling

126.

Impersonation Attacks:

Stealing credentials

a)

Phishing

b)

Spear Phishing

c)

Whaling

d)

Pharming

127.

Impersonation Attacks:

Targeted attack

a)

Spear Phishing

b)

Whaling

c)

Pharming

d)

Vishing

128.

Impersonation Attacks:

Targeted attacks on executives

a)

Whaling

b)

Pharming

c)

Vishing

d)

Smishing and SPIM

129.

Impersonation Attacks:

Using fake websites

a)

Pharming

b)

Vishing

c)

Smishing and SPIM

d)

Spoofing

130.

Impersonation Attacks:

Voice phishing

a)

Vishing

b)

Smishing and SPIM

c)

Spoofing

d)

Spam

131.

Impersonation Attacks:

SMS and IM spam

a)

Smishing and SPIM

b)

Spoofing

c)

Spam

d)

Phishing

132.

Impersonation Attacks:

Faking and identity

a)

Spoofing

b)

Spam

c)

Phishing

d)

Spear Phishing

133.

Security training programs help (a)   users about risks

134.

Security Education Programs:

1) Provides users with the knowledge they need to protect the organization's security

a)

Security Training

b)

Security Awareness

135.

Security Education Programs:

2) Keeps the lessons learns learned during security training top of mind for employees

a)

Security Awareness

b)

Security Training

136.

*Instruction in on-site classes

*Instruction with orientations

*Education through online computer-based training providers

*Participation in vendor-provided classroom training

a)

Security Training Methods

b)

Use Diversity of Training Techniques

c)

Training Frequency

137.

*Phishing simulations

*Gamification

*Capture the Flag exercises

a)

Use a Diversity of Training Techniques

b)

Training Frequency

c)

Security Training Methods

138.

Customize training based upon (a)   roles

139.

*Initial training for new employees

*Update training for employees with new roles

*Refresher training on a annual basis

*Awareness efforts throughout the year

a)

Training Frequency

b)

Use a Diversity of Training Techniques

c)

Security Training Methods

140.

Review training materials regularly to ensure relevance

a)

True

b)

False