Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

ASYC DOM2.2 XEBYS

Total questions: 151

Worksheet time: 1hrs 16mins

Name
Class
Date
1.

Raphael discovered during a vulnerability scan that an administrative interface to one of his

storage systems was inadvertently exposed to the Internet. He is reviewing firewall logs and

would like to determine whether any access attempts came from external sources. Which

one of the following IP addresses reflects an external source?

a)

10.15.1.100

b)

12.8.1.100

c)

172.16.1.100

d)

192.168.1.100

2.

Nick is configuring vulnerability scans for his network using a third-party

vulnerability scanning service. He is attempting to scan a web server that he knows exposes a CIFS file

share and contains several significant vulnerabilities. However, the scan results only show

ports 80 and 443 as open. What is the most likely cause of these scan results?

a)

The CIFS file share is running on port 443.

b)

A firewall configuration is preventing the scan from succeeding.

c)

The scanner configuration is preventing the scan from succeeding.

d)

The CIFS file share is running on port 80.

3.

Thomas learned this morning of a critical security flaw that affects a major service used by

his organization and requires immediate patching. This flaw was the subject of news reports

and is being actively exploited. Thomas has a patch and informed stakeholders of the issue

and received permission to apply the patch during business hours. How should he handle

the change management process?

a)

Thomas should apply the patch and then follow up with an emergency change request

after work is complete.

b)

Thomas should initiate a standard change request but apply the patch before waiting

for approval.

c)

Thomas should work through the standard change approval process and wait until it

is complete to apply the patch.

d)

Thomas should file an emergency change request and wait until it is approved to apply

the patch.

4.

After running a vulnerability scan of systems in his organization’s development shop,

Mike discovers the issue shown here on several systems. What is the best solution to this

vulnerability?

a)

Apply the required security patches to this framework.

b)

Remove this framework from the affected systems.

c)

Upgrade the operating system of the affected systems.

d)

No action is necessary.

5.

Tran is preparing to conduct vulnerability scans against a set of workstations in his organization.

He is particularly concerned about system configuration settings. Which one of the

following scan types will give him the best results?

a)

Unauthenticated scan

b)

Credentialed scan

c)

External scan

d)

Internal scan

6.

Brian is configuring a vulnerability scan of all servers in his organization’s datacenter. He

is configuring the scan to detect only the highest-severity

vulnerabilities. He would like to

empower system administrators to correct issues on their servers but also have some insight

into the status of those remediations. Which approach would best serve Brian’s interests?

a)

Give the administrators access to view the scans in the vulnerability scanning system.

b)

Send email alerts to administrators when the scans detect a new vulnerability on their

servers.

c)

Configure the vulnerability scanner to open a trouble ticket when they detect a new

vulnerability on a server.

d)

Configure the scanner to send reports to Brian who can notify administrators and

track them in a spreadsheet.

7.

Xiu Ying is configuring a new vulnerability scanner for use in her organization’s datacenter.

Which one of the following values is considered a best practice for the scanner’s update

frequency?

a)

Daily

b)

Weekly

c)

Monthly

d)

Quarterly

8.

Ben’s manager recently assigned him to begin the remediation work on the most vulnerable

server in his organization. A portion of the scan report appears here. What remediation

action should Ben take first?

a)

Install patches for Adobe Flash.

b)

Install patches for Firefox.

c)

Run Windows Update.

d)

Remove obsolete software.

9.

Zhang Wei completed a vulnerability scan of his organization’s virtualization platform from

an external host and discovered the vulnerability shown here. How should he react?

a)

This is a critical issue that requires immediate adjustment of firewall rules.

b)

This issue has a very low severity and does not require remediation.

c)

This issue should be corrected as time permits.

d)

This is a critical issue, and Zhang Wei should shut down the platform until it is

corrected.

10.

Elliott runs a vulnerability scan of one of the servers belonging to his organization and finds

the results shown here. Which one of these statements is not correct?

a)

This server requires one or more Linux patches.

b)

This server requires one or more Oracle database patches.

c)

This server requires one or more Firefox patches.

d)

This server requires one or more MySQL patches.

11.

Tom runs a vulnerability scan of the file server shown here.

a)

Block RDP access to this server from all hosts.

b)

Review and secure server accounts.

c)

Upgrade encryption on the server.

d)

No action is required.

12.

Dave is running a vulnerability scan of a client’s network for the first time. The client has

never run such a scan and expects to find many results. What security control is likely to

remediate the largest portion of the vulnerabilities discovered in Dave’s scan?

a)

Input validation

b)

Patching

c)

Intrusion prevention systems

d)

Encryption

13.

Kai is planning to patch a production system to correct a vulnerability detected during a

scan. What process should she follow to correct the vulnerability but minimize the risk of a

system failure?

a)

Kai should deploy the patch immediately on the production system.

b)

Kai should wait 60 days to deploy the patch to determine whether bugs are reported.

c)

Kai should deploy the patch in a sandbox environment to test it prior to applying it in

production.

d)

Kai should contact the vendor to determine a safe timeframe for deploying the patch in

production.

14.

Given no other information, which one of the following vulnerabilities would you consider

the greatest threat to information confidentiality?

a)

HTTP TRACE/TRACK methods enabled

b)

SSL Server with SSL v3 enabled vulnerability

c)

phpinfo information disclosure vulnerability

d)

Web application SQL injection vulnerability

15.

Ling recently completed the security analysis of a web browser deployed on systems

in her organization and discovered that it is susceptible to a zero-day

integer overflow

attack. Who is in the best position to remediate this vulnerability in a manner that allows

continued use of the browser?

a)

Ling

b)

The browser developer

c)

The network administrator

d)

The domain administrator

16.

Jeff’s team is preparing to deploy a new database service, and he runs a vulnerability scan

of the test environment. This scan results in the four vulnerability reports shown here. Jeff is

primarily concerned with correcting issues that may lead to a confidentiality breach. Which

vulnerability should Jeff remediate first?

a)

Rational ClearCase Portscan Denial of Service vulnerability

b)

Non-Zero

Padding Bytes Observed in Ethernet Packets

c)

Oracle Database TNS Listener Poison Attack vulnerability

d)

Hidden RPC Services

17.

Eric is a security consultant and is trying to sell his services to a new client. He would like

to run a vulnerability scan of their network prior to their initial meeting to show the client

the need for added security. What is the most significant problem with this approach?

a)

Eric does not know the client’s infrastructure design.

b)

Eric does not have permission to perform the scan.

c)

Eric does not know what operating systems and applications are in use.

d)

Eric does not know the IP range of the client’s systems.

18.

Renee is assessing the exposure of her organization to the denial-of-

service vulnerability in the scan report shown here. She is specifically interested in determining whether an external attacker would be able to exploit the denial-of-service vulnerability. Which one of the following

sources of information would provide her with the best information to complete this assessment?

a)

Server logs

b)

Firewall rules

c)

IDS configuration

d)

DLP configuration

19.

Mary is trying to determine what systems in her organization should be subject to vulnerability

scanning. She would like to base this decision on the criticality of the system to

business operations. Where should Mary turn to best find this information?

a)

The CEO

b)

System names

c)

IP addresses

d)

Asset inventory

20.

Paul ran a vulnerability scan of his vulnerability scanner and received the result shown here.

What is the simplest fix to this issue?

a)

Upgrade Nessus.

b)

Remove guest accounts.

c)

Implement TLS encryption.

d)

Renew the server certificate.

21.

Kamea is designing a vulnerability management system for her organization. Her highest

priority is conserving network bandwidth. She does not have the ability to alter the configuration

or applications installed on target systems. What solution would work best in

Kamea’s environment to provide vulnerability reports?

a)

Agent-based

scanning

b)

Server-based

scanning

c)

Passive network monitoring

d)

Port scanning

22.

Aki is conducting a vulnerability scan when he receives a report that the scan is slowing

down the network for other users. He looks at the performance configuration settings

shown here. Which setting would be most likely to correct the issue?

a)

Enable safe checks.

b)

Stop scanning hosts that become unresponsive during the scan.

c)

Scan IP addresses in random order.

d)

Max simultaneous hosts per scan.

23.

Laura received a vendor security bulletin that describes a zero-day

vulnerability in her organization’s main database server. This server is on a private network but is used by publicly accessible web applications. The vulnerability allows the decryption of administrative

connections to the server. What reasonable action can Laura take to address this issue as

quickly as possible?

a)

Apply a vendor patch that resolves the issue.

b)

Disable all administrative access to the database server.

c)

Require VPN access for remote connections to the database server.

d)

Verify that the web applications use strong encryption.

24.

Emily discovered the vulnerability shown here on a server running in her organization.

What is the most likely underlying cause for this vulnerability?

a)

Failure to perform input validation

b)

Failure to use strong passwords

c)

Failure to encrypt communications

d)

Failure to install antimalware software

25.

Rex recently ran a vulnerability scan of his organization’s network and received the results

shown here. He would like to remediate the server with the highest number of the most

serious vulnerabilities first. Which one of the following servers should be on his highest priority list?

a)

10.0.102.58

b)

10.0.16.58

c)

10.0.46.116

d)

10.0.69.232

26.

Abella is configuring a vulnerability scanning tool. She recently learned about a privilege

escalation vulnerability that requires the user already have local access to the system. She

would like to ensure that her scanners are able to detect this vulnerability as well as future

similar vulnerabilities. What action can she take that would best improve the scanner’s

ability to detect this type of issue?

a)

Enable credentialed scanning.

b)

Run a manual vulnerability feed update.

c)

Increase scanning frequency.

d)

Change the organization’s risk appetite.

27.

Kylie reviewed the vulnerability scan report for a web server and found that it has multiple

SQL injection and cross-site scripting vulnerabilities. What would be the least difficult way

for Kylie to address these issues?

a)

Install a web application firewall.

b)

Recode the web application to include input validation.

c)

Apply security patches to the server operating system.

d)

Apply security patches to the web server service.

28.

Karen ran a vulnerability scan of a web server used on her organization’s internal network.

She received the report shown here. What circumstances would lead Karen to dismiss this

vulnerability as a false positive?

a)

The server is running SSL v2.

b)

The server is running SSL v3.

c)

The server is for internal use only.

d)

The server does not contain sensitive information.

29.

Which one of the following vulnerabilities is the most difficult to confirm with an external

vulnerability scan?

a)

Cross-site

scripting

b)

Cross-site

request forgery

c)

Blind SQL injection

d)

Unpatched web server

30.

Holly ran a scan of a server in her datacenter, and the most serious result was the vulnerability

shown here. What action is most commonly taken to remediate this vulnerability?

a)

Remove the file from the server.

b)

Edit the file to limit information disclosure.

c)

Password protect the file.

d)

Limit file access to a specific IP range.

31.

During a recent vulnerability scan, Mark discovered a flaw in an internal web application

that allows cross-site scripting attacks. He spoke with the manager of the team responsible

for that application and was informed that he discovered a known vulnerability and the

manager worked with other leaders and determined that the risk is acceptable and does not

require remediation. What should Mark do?

a)

Object to the manager’s approach and insist on remediation.

b)

Mark the vulnerability as a false positive.

c)

Schedule the vulnerability for remediation in six months.

d)

Mark the vulnerability as an exception.

32.

Jacquelyn recently read about a new vulnerability in Apache web servers that allows

attackers to execute arbitrary code from a remote location. She verified that her servers

have this vulnerability, but this morning’s OpenVAS vulnerability scan report shows that

the servers are secure. She contacted the vendor and determined that they have released a

signature for this vulnerability and it is working properly at other clients. What action can

Jacquelyn take that will most likely address the problem efficiently?

a)

Add the web servers to the scan.

b)

Reboot the vulnerability scanner.

c)

Update the vulnerability feed.

d)

Wait until tomorrow’s scan.

33.

Sharon is designing a new vulnerability scanning system for her organization. She must scan

a network that contains hundreds of unmanaged hosts. Which of the following techniques

would be most effective at detecting system configuration issues in her environment?

a)

Agent-based

scanning

b)

Credentialed scanning

c)

Server-based

scanning

d)

Passive network monitoring

34.

Arlene ran a vulnerability scan of a VPN server used by contractors and employees to gain access to her organization’s network. An external scan of the server found the vulnerability shown here.

Which one of the following hash algorithms would not trigger this vulnerability?

a)

MD4

b)

MD5

c)

SHA-1

d)

SHA-256

35.

What is the most likely result of failing to correct this vulnerability?

a)

All users will be able to access the site.

b)

All users will be able to access the site, but some may see an error message.

c)

Some users will be unable to access the site.

d)

All users will be unable to access the site.

36.

How can Arlene correct this vulnerability?

a)

Reconfigure the VPN server to only use secure hash functions.

b)

Request a new certificate.

c)

Change the domain name of the server.

d)

Implement an intrusion prevention system.

37.

After reviewing the results of a vulnerability scan, Bruce discovered that many of the servers

in his organization are susceptible to a brute-force

SSH attack. He would like to determine

what external hosts attempted SSH connections to his servers and is reviewing firewall logs.

What TCP port would relevant traffic most likely use?

a)

22

b)

636

c)

1433

d)

1521

38.

Joaquin runs a vulnerability scan of the network devices in his organization and sees the

vulnerability report shown here for one of those devices. What action should he take?

a)

No action is necessary because this is an informational report.

b)

Upgrade the version of the certificate.

c)

Replace the certificate.

d)

Verify that the correct ciphers are being used.

39.

Lori is studying vulnerability scanning as she prepares for the CySA+ exam. Which of the

following is not one of the principles she should observe when preparing for the exam to

avoid causing issues for her organization?

a)

Run only nondangerous scans on production systems to avoid disrupting a production

service.

b)

Run scans in a quiet manner without alerting other IT staff to the scans or their results

to minimize the impact of false information.

c)

Limit the bandwidth consumed by scans to avoid overwhelming an active network

link.

d)

Run scans outside of periods of critical activity to avoid disrupting the business.

40.

Meredith is configuring a vulnerability scan and would like to configure the scanner to perform

credentialed scans. Of the menu options shown here, which will allow her to directly

configure this capability?

a)

Manage Discovery Scans

b)

Configure Scan Settings

c)

Configure Search Lists

d)

Set Up Host Authentication

41.

Norman is working with his manager to implement a vulnerability management program

for his company. His manager tells him that he should focus on remediating critical and

high-severity risks and that the organization does not want to spend time worrying about

risks rated medium or lower. What type of criteria is Norman’s manager using to make this

decision?

a)

Risk appetite

b)

False positive

c)

False negative

d)

Data classification

42.

Sara’s organization has a well-managed

test environment. What is the most likely issue that

Sara will face when attempting to evaluate the impact of a vulnerability remediation by first

deploying it in the test environment?

a)

Test systems are not available for all production systems.

b)

Production systems require a different type of patch than test systems.

c)

Significant configuration differences exist between test and production systems.

d)

Test systems are running different operating systems than production systems.

43.

How many vulnerabilities listed in the report shown here are significant enough to warrant

immediate remediation in a typical operating environment?

a)

22

b)

14

c)

5

d)

0

44.

Which one of the following types of data is subject to regulations in the United States that

specify the minimum frequency of vulnerability scanning?

a)

Driver’s license numbers

b)

Insurance records

c)

Credit card data

d)

Medical records

45.

Chang is responsible for managing his organization’s vulnerability scanning program. He

is experiencing issues with scans aborting because the previous day’s scans are still running

when the scanner attempts to start the current day’s scans. Which one of the following solutions

is least likely to resolve Chang’s issue?

a)

Add a new scanner.

b)

Reduce the scope of the scans.

c)

Reduce the sensitivity of the scans.

d)

Reduce the frequency of the scans.

46.

Bhanu is scheduling vulnerability scans for her organization’s datacenter. Which one of the

following is a best practice that Bhanu should follow when scheduling scans?

a)

Schedule scans so that they are spread evenly throughout the day.

b)

Schedule scans so that they run during periods of low activity.

c)

Schedule scans so that they all begin at the same time.

d)

Schedule scans so that they run during periods of peak activity to simulate

performance under load.

47.

Alan recently reviewed a vulnerability report and determined that an insecure direct object

reference vulnerability existed on the system. He implemented a remediation to correct the

vulnerability. After doing so, he verifies that his actions correctly mitigated the vulnerability.

What term best describes the initial vulnerability report?

a)

True positive

b)

True negative

c)

False positive

d)

False negative

48.

Gwen is reviewing a vulnerability report and discovers that an internal system contains a

serious flaw. After reviewing the issue with her manager, they decide that the system is sufficiently

isolated and they will take no further action. What risk management strategy are

they adopting?

a)

Risk avoidance

b)

Risk mitigation

c)

Risk transference

d)

Risk acceptance

49.

Mike is in charge of the software testing process for his company. They perform a complete

set of tests for each product throughout its life span. Use your knowledge of software

assessment methods to answer the following questions.

A new web application has been written by the development team in Mike’s company. They

used an Agile process and built a tool that fits all of the user stories that the participants

from the division that asked for the application outlined. If they want to ensure that the

functionality is appropriate for all users in the division, what type of testing should Mike

perform?

a)

Stress testing

b)

Regression testing

c)

Static testing

d)

User acceptance testing

50.

Mike is in charge of the software testing process for his company. They perform a complete

set of tests for each product throughout its life span. Use your knowledge of software

assessment methods to answer the following questions.

Mike’s development team wants to expand the use of the software to the whole company,

but they are concerned about its performance. What type of testing should they conduct to

ensure that the software will not fail under load?

a)

Stress testing

b)

Regression testing

c)

Static testing

d)

User acceptance testing

51.

Mike is in charge of the software testing process for his company. They perform a complete

set of tests for each product throughout its life span. Use your knowledge of software

assessment methods to answer the following questions.

Two years after deployment, Mike’s team is ready to roll out a major upgrade to their web

application. They have pulled code from the repository that it was checked into but are

worried that old bugs may have been reintroduced because they restored additional functionality

based on older code that had been removed in a release a year ago. What type of

testing does Mike’s team need to perform?

a)

Stress testing

b)

Regression testing

c)

Static testing

d)

User acceptance testing

52.

Padma is evaluating the security of an application developed within her organization. She

would like to assess the application’s security by supplying it with invalid inputs. What

technique is Padma planning to use?

a)

Fault injection

b)

Stress testing

c)

Mutation testing

d)

Fuzz testing

53.

Which software development life cycle model is illustrated in the image?

a)

Waterfall

b)

Spiral

c)

Agile

d)

RAD

54.

The Open Worldwide Application Security Project (OWASP) maintains an application

called Orizon. This application reviews Java classes and identifies potential security flaws.

What type of tool is Orizon?

a)

Fuzzer

b)

Static code analyzer

c)

Web application assessor

d)

Fault injector

55.

Barney’s organization mandates fuzz testing for all applications before deploying them

into production. Which one of the following issues is this testing methodology most likely

to detect?

a)

Incorrect firewall rules

b)

Unvalidated input

c)

Missing operating system patches

d)

Unencrypted data transmission

56.

Mia would like to ensure that her organization’s cybersecurity team reviews the architecture

of a new ERP application that is under development. During which SDLC phase should

Mia expect the security architecture to be completed?

a)

Analysis and Requirements Definition

b)

Design

c)

Development

d)

Testing and Integration

57.

Which one of the following security activities is not normally a component of the Operations

and Maintenance phase of the SDLC?

a)

Vulnerability scans

b)

Disposition

c)

Patching

d)

Regression testing

58.

Olivia has been put in charge of performing code reviews for her organization and needs

to determine which code analysis models make the most sense based on specific needs her

organization has. Use your knowledge of code analysis techniques to answer the following

questions.

Olivia’s security team has identified potential malicious code that has been uploaded to

a webserver. If she wants to review the code without running it, what technique should

she use?

a)

Dynamic analysis

b)

Fagan analysis

c)

Regression analysis

d)

Static analysis

59.

Olivia’s next task is to test the code for a new mobile application. She needs to test it by

executing the code and intends to provide the application with input based on testing scenarios

created by the development team as part of their design work. What type of testing

will Olivia conduct?

a)

Dynamic analysis

b)

Fagan analysis

c)

Regression analysis

d)

Static analysis

60.

After completing the first round of tests for her organization’s mobile application, Olivia

has discovered indications that the application may not handle unexpected data well. What

type of testing should she conduct if she wants to test it using an automated tool that will

check for this issue?

a)

Fault injection

b)

Fagan testing

c)

Fuzzing

d)

Failure injection

61.

Which one of the following characters would not signal a potential security issue during the

validation of user input to a web application?

a)

<

b)

'

c)

>

d)

$

62.

The Open Worldwide Application Security Project (OWASP) maintains a listing of the most

important web application security controls. Which one of these items is least likely to

appear on that list?

a)

Implement identity and authentication controls.

b)

Implement appropriate access controls.

c)

Obscure web interface locations.

d)

Leverage security frameworks and libraries.

63.

Kyle is developing a web application that uses a database back end. He is concerned about

the possibility of an SQL injection attack against his application and is consulting the

OWASP proactive security controls list to identify appropriate controls. Which one of the

following OWASP controls is least likely to prevent a SQL injection attack?

a)

Parameterize queries.

b)

Validate all input.

c)

Encode data.

d)

Implement logging and intrusion detection.

64.

Jill’s organization has adopted an asset management tool. If she wants to identify systems

on the network based on a unique identifier per machine that will not normally change over

time, which of the following options can she use for network-based

discovery?

a)

IP address

b)

Hostname

c)

MAC address

d)

None of the above

65.

Which software development methodology is illustrated in the diagram?

a)

Spiral

b)

RAD

c)

Agile

d)

Waterfall

66.

Claire knows that a web application that her organization needs to have in production has

vulnerabilities due to a recent scan using a web application security scanner. What is her

best protection option if she knows that the vulnerability is a known SQL injection flaw?

a)

A firewall

b)

An IDS

c)

A WAF

d)

DLP

67.

Donna has been assigned as the security lead for a DevSecOps team building a new web

application. As part of the effort, she has to oversee the security practices that the team will

use to protect the application. Use your knowledge of secure coding practices to help Donna

guide her team through this process.

A member of Donna’s team recommends building a blocklist to avoid dangerous characters

like ' and <script> tags. How could attackers bypass a blocklist that individually identified

those characters?

a)

They can use a binary attack.

b)

They can use alternate encodings.

c)

They can use different characters with the same meaning.

d)

The characters could be used together to avoid the blocklist.

68.

Donna has been assigned as the security lead for a DevSecOps team building a new web

application. As part of the effort, she has to oversee the security practices that the team will

use to protect the application. Use your knowledge of secure coding practices to help Donna

guide her team through this process.

The design of the application calls for client-side

validation of input. What type of tool

could an attacker use to bypass this?

a)

An XSS injector

b)

A web proxy

c)

A JSON interpreter

d)

A SQL injector

69.

Donna has been assigned as the security lead for a DevSecOps team building a new web

application. As part of the effort, she has to oversee the security practices that the team will

use to protect the application. Use your knowledge of secure coding practices to help Donna

guide her team through this process.

A member of Donna’s security team suggests that output encoding should also be considered.

What type of attack is the team member most likely attempting to prevent?

a)

Cross-site

scripting

b)

SQL injection

c)

Cross-site

request forgery

d)

All of the above

70.

Nathan downloads a BIOS/UEFI update from Dell’s website, and when he attempts to

install it on the PC, he receives an error that the hash of the download does not match the

hash stored on Dell’s servers. What type of protection is this?

a)

Full-disk

encryption

b)

Firmware protection

c)

Operating system protection

d)

None of the above

71.

What practice is typical in a DevSecOps organization as part of a CI/CD pipeline?

a)

Automating some security gates

b)

Programmatic implementation of zero-day

vulnerabilities

c)

Using security practitioners to control the flow of the CI/CD pipeline

d)

Removing security features from the IDE

72.

Valerie wants to prevent potential cross-site

scripting attacks from being executed when

previously entered information is displayed in user’s browsers. What technique should she

use to prevent this?

a)

A firewall

b)

A HIDS

c)

Output encoding

d)

String randomization

73.

While developing a web application, Chris sets his session ID length to 128 bits based on

OWASP’s recommended session management standards. What reason would he have for

needing such a long session ID?

a)

To avoid duplication

b)

To allow for a large group of users

c)

To prevent brute-forcing

d)

All of the above

74.

Robert is reviewing a web application, and the developers have offered four different

responses to incorrect logins. Which of the following four responses is the most

secure option?

a)

Login failed for user; invalid password

b)

Login failed; invalid user ID or password

c)

Login failed; invalid user ID

d)

Login failed; account does not exist

75.

Nathan is reviewing PHP code for his organization and finds the following code in the

application he is assessing. What technique is the developer using?

a)

Dynamic binding

b)

Parameterized queries

c)

Variable limitation

d)

None of the above

76.

Christina wants to check the firmware she has been provided to ensure that it is the same

firmware that the manufacturer provides. What process should she follow to validate that

the firmware is trusted firmware?

a)

Download the same file from the manufacturer and compare file size.

b)

Compare a hash of the file to a hash provided by the manufacturer.

c)

Run strings against the firmware to find any evidence of tempering.

d)

Submit the firmware to a malware scanning site to verify that it does not contain

malware.

77.

What type of attack is the use of query parameterization intended to prevent?

a)

Buffer overflows

b)

Cross-site

scripting

c)

SQL injection

d)

Denial-of-

service

attacks

78.

What type of attack is output encoding typically used against?

a)

DoS

b)

XSS

c)

XML

d)

DDoS

79.

Scott has been asked to select a software development model for his organization and knows

that there are a number of models that may make sense for what he has been asked to

accomplish. Use your knowledge of SDLC models to identify an appropriate model for each

of the following requirements.

Scott’s organization needs basic functionality of the effort to become available as soon as

possible and wants to involve the teams that will use it heavily to ensure that their needs are

met. What model should Scott recommend?

a)

Waterfall

b)

Spiral

c)

Agile

d)

Rapid Application Development

80.

Scott has been asked to select a software development model for his organization and knows

that there are a number of models that may make sense for what he has been asked to

accomplish. Use your knowledge of SDLC models to identify an appropriate model for each

of the following requirements.

A parallel coding effort needs to occur; however, this effort involves a very complex system

and errors could endanger human lives. The system involves medical records and drug

dosages, and the organization values stability and accuracy over speed. Scott knows the

organization often adds design constraints throughout the process and that the model he

selects must also deal with that need. What model should he choose?

a)

Waterfall

b)

Spiral

c)

Agile

d)

Rapid Application Development

81.

Scott has been asked to select a software development model for his organization and knows

that there are a number of models that may make sense for what he has been asked to

accomplish. Use your knowledge of SDLC models to identify an appropriate model for each

of the following requirements.

At the end of his development cycle, what SDLC phase will Scott enter as the new application

is installed and replaces the old code?

a)

User acceptance testing

b)

Testing and integration

c)

Disposition

d)

Redesign

82.

The OWASP Session Management Cheatsheet advises that session IDs are meaningless and

recommends that they should be used only as an identifier on the client side. Why should

a session ID not have additional information encoded in it like the IP address of the client,

their username, or other information?

a)

Processing complex session IDs will slow down the service.

b)

Session IDs cannot contain this information for legal reasons.

c)

Session IDs are sent to multiple different users, which would result in a data breach.

d)

Session IDs could be decoded, resulting in data leakage.

83.

Bounds checking, removing special characters, and forcing strings to match a limited set of

options are all examples of what web application security technique?

a)

SQL injection prevention

b)

Input validation

c)

XSS prevention

d)

Fuzzing

84.

Abigail is performing input validation against an input field and uses the following regular

expression:

What is she checking with the regular expression?

a)

She is removing all typical special characters found in SQL injection.

b)

She is checking for all U.S. state names.

c)

She is removing all typical special characters for cross-site

scripting attacks.

d)

She is checking for all U.S. state name abbreviations.

85.

Jennifer uses an application to send randomized data to her application to determine how it

responds to unexpected input. What type of tool is she using?

a)

A UAT tool

b)

A stress testing tool

c)

A fuzzer

d)

A regression testing tool

86.

Greg wants to prevent SQL injection in a web application he is responsible for. Which of

the following is not a common defense against SQL injection?

a)

Prepared statements with parameterized queries

b)

Output validation

c)

Stored procedures

d)

Escaping all user-supplied

input

87.

While reviewing code that generates a SQL query, Aarav notices that the “address” field is

appended to the query without input validation or other techniques applied. What type of

attack is most likely to be successful against code like this?

a)

DoS

b)

XSS

c)

SQL injection

d)

Teardrop

88.

Amanda has been assigned to lead the development of a new web application for her

organization. She is following a standard SDLC model as shown here. Use the model and

your knowledge of the software development life cycle to answer the following questions.

Amanda’s first task is to determine if there are alternative solutions that are more cost effective

than in-house development. What phase is she in?

a)

Design

b)

Operations and maintenance

c)

Feasibility

d)

Analysis and requirements definition

89.

Amanda has been assigned to lead the development of a new web application for her

organization. She is following a standard SDLC model as shown here. Use the model and

your knowledge of the software development life cycle to answer the following questions.

What phase of the SDLC typically includes the first code analysis and unit testing in the

process?

a)

Analysis and requirements definition

b)

Design

c)

Coding

d)

Testing and integration

90.

Amanda has been assigned to lead the development of a new web application for her

organization. She is following a standard SDLC model as shown here. Use the model and

your knowledge of the software development life cycle to answer the following questions.

After making it through most of the SDLC process, Amanda has reached point E on the

diagram. What occurs at point E?

a)

Disposition

b)

Training and transition

c)

Unit testing

d)

Testing and integration

91.

Angela wants to prevent buffer overflow attacks on a Windows system. What two built-in

technologies should she consider?

a)

The memory firewall and the stack guard

b)

ASLR and DEP

c)

ASLR and DLP

d)

The memory firewall and the buffer guard

92.

Amanda has been assigned to reduce the attack surface area for her organization, and she

knows that the current network design relies on allowing systems throughout her organization

to access the Internet directly via public IP addresses they are assigned. What should

her first step be to reduce her organization’s attack surface quickly and without large

amounts of time invested?

a)

Install host firewalls on the systems.

b)

Move to a NAT environment.

c)

Install an IPS.

d)

None of the above.

93.

Matt believes that developers in his organization deployed code that did not implement

cookies in a secure way. What type of attack would be aided by this security issue?

a)

SQL injection

b)

A denial-of-

service

attack

c)

Session hijacking

d)

XSS

94.

Chris operates the point-of-sale

(POS) network for a company that accepts credit cards and

is thus required to be compliant with PCI DSS. During his regular assessment of the POS

terminals, he discovers that a recent Windows operating system vulnerability exists on all

of them. Since they are all embedded systems that require a manufacturer update, he knows

that he cannot install the available patch. What is Chris’s best option to stay compliant with

PCI DSS and protect his vulnerable systems?

a)

Replace the Windows embedded point-of-

sale

terminals with standard Windows

systems.

b)

Build a custom operating system image that includes the patch.

c)

Identify, implement, and document compensating controls.

d)

Remove the POS terminals from the network until the vendor releases a patc

95.

Tracy is validating the web application security controls used by her organization. She

wants to ensure that the organization is prepared to conduct forensic investigations of

future security incidents. Which one of the following OWASP control categories is most

likely to contribute to this effort?

a)

Implement logging.

b)

Validate all inputs.

c)

Parameterize queries.

d)

Error and exception handling.

96.

While reviewing his Apache logs, Oscar discovers the following entry. What has occurred?

a)

A successful database query

b)

A PHP overflow attack

c)

A SQL injection attack

d)

An unsuccessful database query

97.

Joan is working as a security consultant to a company that runs a critical web application.

She discovered that the application has a serious SQL injection vulnerability, but the

company cannot take the system offline during the two weeks required to revise the code.

Which one of the following technologies would serve as the best compensating control?

a)

IPS

b)

WAF

c)

Vulnerability scanning

d)

Encryption

98.

After conducting an nmap scan of his network from outside of his network, James notes

that a large number of devices are showing three TCP ports open on public IP addresses:

9100, 515, and 631. What type of devices has he found, and how could he reduce his

organization’s attack surface?

a)

Wireless access points, disable remote administration

b)

Desktop workstations, enable the host firewall

c)

Printers, move the printers to an internal-only

IP address range

d)

Network switches, enable encrypted administration mode

99.

Alex is working to understand his organization’s attack surface. Services, input fields in a

web application, and communication protocols are all examples of what component of an

attack surface evaluation?

a)

Threats

b)

Attack vectors

c)

Risks

d)

Surface tension

100.

Michelle wants to implement a static application security testing (SAST) tool into her

continuous integration pipeline. What challenge could she run into if her organization

uses multiple programming languages for components of their application stack that will

be tested?

a)

They will have to ensure the scanner works with all of the languages chosen

b)

They will have to compile all of the code to the same binary output language.

c)

They will have to run the applications in a sandbox.

d)

They will have to run the applications under the same execution environment.

101.

Ken learns that an APT group is targeting his organization. What term best describes this

situation?

a)

Risk

b)

Threat

c)

Countermeasure

d)

Vulnerability

102.

Which one of the following activities is least likely to occur during the risk identification

process?

a)

Network segmentation

b)

Threat intelligence

c)

Vulnerability scanning

d)

System assessments

103.

What two factors are weighted most heavily when determining the severity of a risk?

a)

Probability and magnitude

b)

Likelihood and probability

c)

Magnitude and impact

d)

Impact and control

104.

Preemployment background screening is an example of what type of security control?

a)

Detective

b)

Preventive

c)

Corrective

d)

Compensating

105.

Roland received a security assessment report from a third-party

assessor, and it indicated

that one of the organization’s web applications is susceptible to an OAuth redirect attack.

What type of attack would this vulnerability allow an attacker to wage?

a)

Privilege escalation

b)

Cross-site

scripting

c)

SQL injection

d)

Impersonation

106.

Gary recently conducted a comprehensive security review of his organization. He identified

the 25 top risks to the organization and is pursuing different risk management strategies for

each of these risks. In some cases, he is using multiple strategies to address a single risk. His

goal is to reduce the overall level of risk so that it lies within his organization’s risk tolerance.

Gary decides that the organization should integrate a threat intelligence feed with the firewall.

What type of risk management strategy is this?

a)

Risk mitigation

b)

Risk acceptance

c)

Risk transference

d)

Risk avoidance

107.

Gary recently conducted a comprehensive security review of his organization. He identified

the 25 top risks to the organization and is pursuing different risk management strategies for

each of these risks. In some cases, he is using multiple strategies to address a single risk. His

goal is to reduce the overall level of risk so that it lies within his organization’s risk tolerance.

Gary discovers that his organization is storing some old files in a cloud service that are

exposed to the world. He deletes those files. What type of risk management strategy is this?

a)

Risk mitigation

b)

Risk acceptance

c)

Risk transference

d)

Risk avoidance

108.

Gary recently conducted a comprehensive security review of his organization. He identified

the 25 top risks to the organization and is pursuing different risk management strategies for

each of these risks. In some cases, he is using multiple strategies to address a single risk. His

goal is to reduce the overall level of risk so that it lies within his organization’s risk tolerance.

Gary is working with his financial team to purchase a cyber-liability

insurance policy to cover the financial impact of a data breach. What type of risk management strategy is

he using?

a)

Risk mitigation

b)

Risk acceptance

c)

Risk transference

d)

Risk avoidance

109.

Which one of the following risk management strategies is most likely to limit the probability

of a risk occurring?

a)

Risk acceptance

b)

Risk avoidance

c)

Risk transference

d)

Risk mitigation

110.

Saanvi would like to reduce the probability of a data breach that affects sensitive personal

information. Which one of the following compensating controls is most likely to achieve

that objective?

a)

Minimizing the amount of data retained and the number of places where it is stored

b)

Limiting the purposes for which data may be used

c)

Purchasing cyber-risk

insura

d)

Installing a new firewall

111.

Kwame recently completed a risk assessment and is concerned that the level of residual risk

exceeds his organization’s risk tolerance. What should he do next?

a)

Have a discussion with his manager.

b)

Implement new security controls.

c)

Modify business processes to lower risk.

d)

Purge data from systems.

112.

Alan is a risk manager for Acme University, a higher education institution located in the

western United States. He is concerned about the threat that an earthquake will damage his

organization’s primary datacenter. He recently undertook a replacement cost analysis and

determined that the datacenter is valued at $10 million.

After consulting with seismologists, Alan determined that an earthquake is expected in the

area of the datacenter once every 200 years. Datacenter specialists and architects helped

him determine that an earthquake would likely cause $5 million in damage to the facility.

Based on the information in this scenario, what is the exposure factor (EF) for the effect of

an earthquake on Acme University’s datacenter?

a)

10 percent

b)

25 percent

c)

50 percent

d)

75 percent

113.

Alan is a risk manager for Acme University, a higher education institution located in the

western United States. He is concerned about the threat that an earthquake will damage his

organization’s primary datacenter. He recently undertook a replacement cost analysis and

determined that the datacenter is valued at $10 million.

After consulting with seismologists, Alan determined that an earthquake is expected in the

area of the datacenter once every 200 years. Datacenter specialists and architects helped

him determine that an earthquake would likely cause $5 million in damage to the facility.

Based on the information in this scenario, what is the annualized rate of occurrence (ARO)

for an earthquake at the datacenter?

a)

.0025

b)

.005

c)

.01

d)

.015

114.

Alan is a risk manager for Acme University, a higher education institution located in the

western United States. He is concerned about the threat that an earthquake will damage his

organization’s primary datacenter. He recently undertook a replacement cost analysis and

determined that the datacenter is valued at $10 million.

After consulting with seismologists, Alan determined that an earthquake is expected in the

area of the datacenter once every 200 years. Datacenter specialists and architects helped

him determine that an earthquake would likely cause $5 million in damage to the facility.

Based on the information in this scenario, what is the annualized loss expectancy (ALE) for

an earthquake at the datacenter?

a)

$25,000

b)

$50,000

c)

$250,000

d)

$500,000

115.

Alan is a risk manager for Acme University, a higher education institution located in the

western United States. He is concerned about the threat that an earthquake will damage his

organization’s primary datacenter. He recently undertook a replacement cost analysis and

determined that the datacenter is valued at $10 million.

After consulting with seismologists, Alan determined that an earthquake is expected in the

area of the datacenter once every 200 years. Datacenter specialists and architects helped

him determine that an earthquake would likely cause $5 million in damage to the facility.

Referring to the previous scenario, if Alan’s organization decides to move the datacenter to

a location where earthquakes are not a risk, what risk management strategy are they using?

a)

Risk mitigation

b)

Risk avoidance

c)

Risk acceptance

d)

Risk transference

116.

Alan is a risk manager for Acme University, a higher education institution located in the

western United States. He is concerned about the threat that an earthquake will damage his

organization’s primary datacenter. He recently undertook a replacement cost analysis and

determined that the datacenter is valued at $10 million.

After consulting with seismologists, Alan determined that an earthquake is expected in the

area of the datacenter once every 200 years. Datacenter specialists and architects helped

him determine that an earthquake would likely cause $5 million in damage to the facility.

Referring to the previous scenario, if the organization decides not to relocate the datacenter

but instead purchases an insurance policy to cover the replacement cost of the datacenter,

what risk management strategy are they using?

a)

Risk mitigation

b)

Risk avoidance

c)

Risk acceptance

d)

Risk transference

117.

Alan is a risk manager for Acme University, a higher education institution located in the

western United States. He is concerned about the threat that an earthquake will damage his

organization’s primary datacenter. He recently undertook a replacement cost analysis and

determined that the datacenter is valued at $10 million.

After consulting with seismologists, Alan determined that an earthquake is expected in the

area of the datacenter once every 200 years. Datacenter specialists and architects helped

him determine that an earthquake would likely cause $5 million in damage to the facility.

Referring to the previous scenario, assume that the organization decides that relocation is

too difficult and the insurance is too expensive. They instead decide that they will carry on

despite the risk of earthquake and handle the impact if it occurs. What risk management

strategy are they using?

a)

Risk mitigation

b)

Risk avoidance

c)

Risk acceptance

d)

Risk transference

118.

Colin would like to implement a detective security control in his accounting department,

which is specifically designed to identify cases of fraud that are able to occur despite the

presence of other security controls. Which one of the following controls is best suited to

meet Colin’s need?

a)

Separation of duties

b)

Least privilege

c)

Dual control

d)

Mandatory vacations

119.

Rob is an auditor reviewing the managerial controls used in an organization. He is examining

the payment process used by the company to issue checks to vendors. He notices

that Helen, a staff accountant, is the person responsible for creating new vendors. Norm,

another accountant, is responsible for issuing payments to vendors. Helen and Norm are

cross-trained to provide backup for each other. What security issue, if any, exists in this

situation?

a)

Least privilege violation

b)

Separation of duties violation

c)

Dual control violation

d)

No issue

120.

Mei recently completed a risk management review and identified that the organization is susceptible to an on-path (also known as man-in-the-middle) attack. After review with her manager, they jointly decided that accepting the risk is the most appropriate strategy. What should Mei do next?

a)

Implement additional security controls.

b)

Design a remediation plan.

c)

Repeat the business impact assessment.

d)

Document the decision.

121.

Robin is planning to conduct a risk assessment in her organization. She is concerned that

it will be difficult to perform the assessment because she needs to include information

about both tangible and intangible assets. What would be the most effective risk assessment

strategy for her to use?

a)

Quantitative risk assessment

b)

Qualitative risk assessment

c)

Combination of quantitative and qualitative risk assessment

d)

Neither quantitative nor qualitative risk assessment

122.

Barry’s organization is running a security exercise and Barry was assigned to conduct offensive

operations. What term best describes Barry’s role in the process?

a)

Red team

b)

Purple team

c)

Blue team

d)

White team

123.

Vlad’s organization recently underwent a security audit that resulted in a finding that the

organization fails to promptly remove the accounts associated with users who have left

the organization. This resulted in at least one security incident where a terminated user

logged into a corporate system and took sensitive information. What identity and access

management control would best protect against this risk?

a)

Automated deprovisioning

b)

Quarterly user account reviews

c)

Separation of duties

d)

Two-person

control

124.

Jay is the CISO for his organization and is responsible for conducting periodic reviews of

the organization’s information security policy. The policy was written three years ago and

has undergone several minor revisions after audits and assessments. Which one of the following

would be the most reasonable frequency to conduct formal reviews of the policy?

a)

Monthly

b)

Quarterly

c)

Annually

d)

Every five years

125.

Terri is undertaking a risk assessment for her organization. Which one of the following

activities would normally occur first?

a)

Risk identification

b)

Risk calculation

c)

Risk mitigation

d)

Risk management

126.

Kai is attempting to determine whether he can destroy a cache of old records that he discovered.

What type of policy would most directly answer his question?

a)

Data ownership

b)

Data classification

c)

Data minimization

d)

Data retention

127.

Fences are a widely used security control that can be described by several different control

types. Which one of the following control types would least describe a fence?

a)

Deterrent

b)

Corrective

c)

Preventive

d)

Physical

128.

Ian is designing an authorization scheme for his organization’s deployment of a new

accounting system. He is considering putting a control in place that would require that two

accountants approve any payment request over $100,000. What security principle is Ian

seeking to enforce?

a)

Security through obscurity

b)

Least privilege

c)

Separation of duties

d)

Dual control

129.

Carmen is working with a new vendor on the design of a penetration test. She would like

to ensure that the vendor does not conduct any physical intrusions as part of their testing.

Where should Carmen document this requirement?

a)

Rules of engagement

b)

Service level objectives

c)

Nondisclosure agreement

d)

Counterparty agreement

130.

Gavin is drafting a document that provides a detailed step-by-

step process that users may

follow to connect to the VPN from remote locations. Alternatively, users may ask IT to help

them configure the connection. What term best describes this document?

a)

Policy

b)

Procedure

c)

Standard

d)

Guideline

131.

Which one of the following security controls is designed to help provide continuity for security

responsibilities?

a)

Succession planning

b)

Separation of duties

c)

Mandatory vacation

d)

Dual control

132.

After conducting a security review, Oskar determined that his organization is not conducting

regular backups of critical data. What term best describes the type of control gap that

exists in Oskar’s organization?

a)

Preventive

b)

Corrective

c)

Detective

d)

Deterrent

133.

Carla is reviewing the cybersecurity policies used by her organization. What policy might

she put in place as a failsafe to cover employee behavior situations where no other policy

directly applies?

a)

Data monitoring policy

b)

Account management policy

c)

Code of conduct

d)

Data ownership policy

134.

Which one of the following items is not normally included in a request for an exception to

security policy?

a)

Description of a compensating control

b)

Description of the risks associated with the exception

c)

Proposed revision to the security policy

d)

Business justification for the exception

135.

What policy should contain provisions for removing user access upon termination?

a)

Data ownership policy

b)

Data classification policy

c)

Data retention policy

d)

Account management policy

136.

Karen is the CISO of a major manufacturer of industrial parts. She is currently performing an

assessment of the firm’s financial controls, with an emphasis on implementing security practices

that will reduce the likelihood of theft from the firm.

Karen would like to ensure that the same individual is not able to both create a new vendor

in the system and authorize a payment to that vendor. She is concerned that an individual

who could perform both of these actions would be able to send payments to false vendors.

What type of control should Karen implement?

a)

Mandatory vacations

b)

Separation of duties

c)

Job rotation

d)

Two-person

control

137.

Karen is the CISO of a major manufacturer of industrial parts. She is currently performing an

assessment of the firm’s financial controls, with an emphasis on implementing security practices

that will reduce the likelihood of theft from the firm.

The accounting department has a policy that requires the signatures of two individuals on

checks valued over $5,000. What type of control do they have in place?

a)

Mandatory vacations

b)

Separation of duties

c)

Job rotation

d)

Two-person

control

138.

Karen is the CISO of a major manufacturer of industrial parts. She is currently performing an

assessment of the firm’s financial controls, with an emphasis on implementing security practices

that will reduce the likelihood of theft from the firm.

Karen would also like to implement controls that would help detect potential malfeasance

by existing employees. Which one of the following controls is least likely to detect

malfeasance?

a)

Mandatory vacations

b)

Separation of duties

c)

Job rotation

d)

Two-person

control

139.

Kevin is conducting a security exercise for his organization that uses both offensive and

defensive operations. His role is to serve as the moderator of the exercise and to arbitrate

disputes. What role is Kevin playing?

a)

White team

b)

Red team

c)

Swiss team

d)

Blue team

140.

Bohai is concerned about access to the main account for a cloud service that his company

uses to manage payment transactions. He decides to implement a new process for multifactor

authentication to that account where an individual on the IT team has the password

to the account, while an individual in the accounting group has the token. What security

principle is Bohai using?

a)

Dual control

b)

Separation of duties

c)

Least privilege

d)

Security through obscurity

141.

Tina is preparing for a penetration test and is working with a new vendor. She wants to

make sure that the vendor understands exactly what technical activities are permitted

within the scope of the test. Where should she document these requirements?

a)

MOA

b)

Contract

c)

RoE

d)

SLA

142.

Azra is reviewing a draft of the Domer Doodads information security policy and finds that

it contains the following statements. Which one of these statements would be more appropriately

placed in a different document?

a)

Domer Doodads designates the chief information security officer as the individual with

primary responsibility for information security.

b)

The chief information security officer is granted the authority to create specific

requirements that implement this policy.

c)

All access to financial systems must use multifactor authentication for remote

connections.

d)

Domer Doodads considers cybersecurity and compliance to be of critical importance

to the business.

143.

Which one of the following security policy framework documents never includes mandatory

employee compliance?

a)

Policy

b)

Guideline

c)

Procedure

d)

Standard

144.

Kaitlyn is on the red team during a security exercise, and she has a question about whether

an activity is acceptable under the exercise’s rules of engagement. Who would be the most

appropriate person to answer her question?

a)

Red team leader.

b)

White team leader.

c)

Blue team leader.

d)

Kaitlyn should act without external advice.

145.

Seamus is conducting a business impact assessment for his organization. He is attempting

to determine the risk associated with a denial-of-service attack against his organization’s datacenter.

Seamus consulted with various subject-matter experts (SMEs) and determined that the attack

would not cause any permanent damage to equipment, applications, or data. The primary

damage would come in the form of lost revenue. Seamus believes that the organization would lose $75,000 in revenue during a successful attack.

Seamus also consulted with his threat management vendor, who considered the probability of

a successful attack against his organization and determined that there is a 10 percent chance

of a successful attack in the next 12 months.

What is the ARO for this assessment?

a)

8 percent

b)

10 percent

c)

12 percent

d)

100 percent

146.

Seamus is conducting a business impact assessment for his organization. He is attempting

to determine the risk associated with a denial-of-service attack against his organization’s datacenter.

Seamus consulted with various subject-matter experts (SMEs) and determined that the attack

would not cause any permanent damage to equipment, applications, or data. The primary

damage would come in the form of lost revenue. Seamus believes that the organization would lose $75,000 in revenue during a successful attack.

Seamus also consulted with his threat management vendor, who considered the probability of

a successful attack against his organization and determined that there is a 10 percent chance

of a successful attack in the next 12 months.

What is the SLE for this scenario?

a)

$625

b)

$6,250

c)

$7,500

d)

$75,000

147.

Seamus is conducting a business impact assessment for his organization. He is attempting

to determine the risk associated with a denial-of-service attack against his organization’s datacenter.

Seamus consulted with various subject-matter experts (SMEs) and determined that the attack

would not cause any permanent damage to equipment, applications, or data. The primary

damage would come in the form of lost revenue. Seamus believes that the organization would lose $75,000 in revenue during a successful attack.

Seamus also consulted with his threat management vendor, who considered the probability of

a successful attack against his organization and determined that there is a 10 percent chance

of a successful attack in the next 12 months.

What is the ALE for this scenario?

a)

$625

b)

$6,250

c)

$7,500

d)

$75,000

148.

Seamus is conducting a business impact assessment for his organization. He is attempting

to determine the risk associated with a denial-of-service attack against his organization’s datacenter.

Seamus consulted with various subject-matter experts (SMEs) and determined that the attack

would not cause any permanent damage to equipment, applications, or data. The primary

damage would come in the form of lost revenue. Seamus believes that the organization would lose $75,000 in revenue during a successful attack.

Seamus also consulted with his threat management vendor, who considered the probability of

a successful attack against his organization and determined that there is a 10 percent chance

of a successful attack in the next 12 months.

Seamus is considering purchasing a DDoS protection system that would reduce the

likelihood of a successful attack. What type of control is he considering?

a)

Detective

b)

Corrective

c)

Preventive

d)

Deterrent

149.

Seamus is conducting a business impact assessment for his organization. He is attempting

to determine the risk associated with a denial-of-service attack against his organization’s datacenter.

Seamus consulted with various subject-matter experts (SMEs) and determined that the attack

would not cause any permanent damage to equipment, applications, or data. The primary

damage would come in the form of lost revenue. Seamus believes that the organization would lose $75,000 in revenue during a successful attack.

Seamus also consulted with his threat management vendor, who considered the probability of

a successful attack against his organization and determined that there is a 10 percent chance

of a successful attack in the next 12 months.

Seamus wants to make sure that he can accurately describe the category of the DDoS protection

service to auditors. Which term best describes the category of this control?

a)

Compensating

b)

Physical

c)

Operational

d)

Technical

150.

Piper’s organization handles credit card information and is, therefore, subject to the Payment

Card Industry Data Security Standard (PCI DSS). She is working to implement the PCI DSS

requirements.

As Piper attempts to implement PCI DSS requirements, she discovers that she is unable to

meet one of the requirements because of a technical limitation in her point-of-

sale system.

She decides to work with regulators to implement a second layer of logical isolation to protect

this system from the Internet to allow its continued operation despite not meeting one

of the requirements. What term best describes the type of control Piper has implemented?

a)

Physical control

b)

Operational control

c)

Compensating control

d)

Deterrent control

151.

Piper’s organization handles credit card information and is, therefore, subject to the Payment

Card Industry Data Security Standard (PCI DSS). She is working to implement the PCI DSS

requirements.

When Piper implements this new isolation technology, what type of risk management action

is she taking?

a)

Risk acceptance

b)

Risk avoidance

c)

Risk transference

d)

Risk mitigation