WorksheetsSec+ Study Quiz 13
Total questions: 42
Worksheet time: 21mins
Which of the following documents specifies what to do in the event of catastrophic loss of a physical or virtual system?
Data retention plan
Incident response plan
Disaster recovery plan
Communication plan
Which of the following roles is responsible for defining the protection type and classification type for a given set of files?
General counsel
Data owner
Risk manager
Chief Information Officer
An employee's company email is configured with conditional access and requires that MFA is enabled and used. An example of MFA is a phone call and:
a push notification
a password
an SMS message
an authentication application
Which of the following is a security implication of newer ICS devices that are becoming more common in corporations?
Devices with cellular communication capabilities bypass traditional network security controls
Many devices do not support elliptic-curve encryption algorithms due to the overhead they require
These devices often lack privacy controls and do not meet newer compliance regulations
Unauthorized voice and audio recording can cause loss of intellectual property
Which of the following is required in order for an IDS and a WAF to be effective on HTTPS traffic?
Hashing
DNS sinkhole
TLS inspection
Data masking
A company policy requires third-party suppliers to self-report data breaches within a specific time frame. Which of the following third-party risk management policies is the company complying with?
MOU
SLA
EOL
NDA
While troubleshooting service disruption on a mission-critical server, a technician discovered the user account that was configured to run automated processes was disabled because the user's password failed to meet password complexity requirements. Which of the following would be the best solution to securely prevent future issues?
Using an administrator account to run the processes and disabling the account when it is not in use
Implementing a shared account the team can use to run automated processes
Configuring a service account to run the processes
Removing the password complexity requirements for the user account
A security analyst is assessing a newly developed web application by testing SQL injection, CSRF, and XML injection. Which of the following frameworks should the analyst consider?
ISO
MITRE ATT&CK
OWASP
NIST
A user's laptop constantly disconnects from the Wi-Fi network. Once the laptop reconnects, the user can reach the internet but cannot access shared folders or other network resources. Which of the following types of attacks is the user most likely experiencing?
Bluejacking
Jamming
Rogue access point
Evil twin
Which of the following procedures would be performed after the root cause of a security incident has been identified to help avoid future incidents from occurring?
Walk-throughs
Lessons learned
Attack framework alignment
Containment
A security administrator is integrating several segments onto a single network. One of the segments, which includes legacy devices, presents a significant amount of risk to the network. Which of the following would allow users to access the legacy devices without compromising the security of the entire network?
NIDS
MAC filtering
Jump server
IPSec
NAT gateway
Which of the following would a security analyst use to determine if other companies in the same sector have seen similar malicious activity against their systems?
Vulnerability scanner
Open-source intelligence
Packet capture
Threat feeds
Which of the following types of disaster recovery plan exercises requires the least interruption to IT operations?
Parallel
Full-scale
Tabletop
Simulation
Which of the following disaster recovery sites is the most cost effective to operate?
Warm site
Cold site
Hot site
Hybrid site
A security operations center wants to implement a solution that can execute files to test for malicious activity. The solution should provide a report of the files' activity against known threats. Which of the following should the security operations center implement?
The Harvester
Nessus
Cuckoo
Sn1per
Which concept should a security administrator utilize to ensure all cloud servers have software preinstalled for vulnerability scanning and continuous monitoring?
Provisioning
Staging
Staging
Quality assurance
What should a network architect implement on a server to maintain network availability if one of the network switches it is connected to goes down?
RAID
UPS
NIC teaming
Load balancing
What might a malicious person be doing to cause an employee to receive multiple messages on a mobile device instructing them to pair the device to an unknown device?
Jamming
Bluesnarfing
Evil twin attack
Rogue access point
Which algorithm should a security administrator use to increase the capacity for an application due to resource exhaustion on another server by splitting the number of connections on each server in half?
Weighted response
Round-robin
Least connection
Weighted least connection
Security analysts use which tool to investigate the issue of a network becoming flooded with malicious packets at specific times of the day?
Web metadata
Bandwidth monitors
System files
Correlation dashboards
What term best describes the activity of a security administrator who performs weekly vulnerability scans on all cloud assets and provides a detailed report?
Continuous deployment
Continuous integration
Data owners
Data processor
Which attack technique involves infecting a website frequently accessed by a company's employees with the hope that the employees' devices will also become infected?
Watering-hole attack
Pretexting
Typosquatting
Impersonation
What technique should a digital forensics team use to obtain a sample of malware that was running in memory but never committed to disk?
pcap reassembly
SSD snapshot
Image volatile memory
Extract from checksums
Which security measure is most likely used to ensure that information provided by a website visitor in a specific field on a form is properly formatted?
Input validation
Code signing
SQL injection
Form submission
When setting up a new firewall on a network segment to allow web traffic while hardening the network, which action would best correct the issue of users receiving errors stating the website could not be located?
Setting an explicit deny to all traffic using port 80 instead of 443
Moving the implicit deny from the bottom of the rule set to the top
Configuring the first line in the rule set to allow all traffic
Ensuring that port 53 has been explicitly allowed in the rule set
Which data classification should be used to secure patient data in a local hospital to ensure it is protected and secure?
Private
Critical
Sensitive
Public
What is the security team most likely to document as a security implication of the current architecture when a small business uses kiosks with end-of-life operating systems?
Patch availability
Product software compatibility
Ease of recovery
Cost of replacement
During a security incident, the security operations team identified sustained network traffic from a malicious IP address: 10.1.4.9. A security analyst is creating an inbound firewall rule to block the IP address from accessing the organization's network. Which of the following fulfills this request?
access-list inbound deny ip source 0.0.0.0/0 destination 10.1.4.9/32
access-list inbound deny ip source 10.1.4.9/32 destination 0.0.0.0/0
access-list inbound permit ip source 10.1.4.9/32 destination 0.0.0.0/0
access-list inbound permit ip source 0.0.0.0/0 destination 10.1.4.9/32
Which of the following is the phase in the incident response process when a security analyst reviews roles and responsibilities?
Preparation
Recovery
Lessons learned
Analysis
Which of the following best describes the action captured in this log file?
Brute-force attack
Privilege escalation
Failed password audit
Forgotten password by the user
Which of the following can be used to identify potential attacker activities without affecting production servers?
Honeypot
Video surveillance
Zero trust
Geofencing
A company wants the ability to restrict web access and monitor the websites that employees visit. Which of the following options would best meet these requirements?
Internet Proxy
VPN
WAF
Firewall
A security analyst notices an unusual amount of traffic hitting the network's edge. Upon examining the logs, the analyst identifies a source IP address and blocks that address to prevent communication with the network. Despite the analyst blocking the address, the attack continues and comes from a large number of different source IP addresses. Which of the following best describes this type of attack?
DDoS
Privilege escalation
DNS poisoning
Buffer overflow
A company needs to centralize its records to create a baseline and have visibility over its security events. Which of the following technologies will achieve this goal?
Security information and event management
Web application firewall
Vulnerability scanner
Next-generation firewall
Two organizations are discussing a possible merger. Both organizations' Chief Financial Officers would like to safely share payroll data with each other to determine if the pay scales for different roles are similar at both organizations. Which of the following techniques would be best to protect employee data while allowing the companies to successfully share this information?
Pseudo-anonymization
Tokenization
Data masking
Encryption
A large retail store's network was breached recently, and this news was made public. The store did not lose any intellectual property, and no customer information was stolen. Although no fines were incurred as a result, the store lost revenue after the breach. Which of the following is the most likely reason for this issue?
Employee training
Leadership changes
Reputation damage
Identity theft
A government organization is developing an advanced AI defense system. Developers are using information collected from third-party providers. Analysts are noticing inconsistencies in the expected progress of the AI learning and attribute the outcome to a recent attack on one of the suppliers. Which of the following is the most likely reason for the inaccuracy of the system?
Improper algorithms security
Tainted training data
Fileless virus
Cryptomalware
Which of the following is the most likely reason for a wireless network outage if the access points are up and running but users in a building near the parking lot cannot connect?
Someone near the building is jamming the signal.
A user has set up a rogue access point near the building.
Someone set up an evil twin access point in the affected area.
The APs in the affected area have been unplugged from the network.
Which of the following can best protect against an employee inadvertently installing malware on a company system?
Host-based firewall
System isolation
Least privilege
Application allow list
An information security officer at a credit card transaction company is conducting a framework-mapping exercise with the internal controls. The company recently established a new office in Europe. Which of the following frameworks should the security officer map the existing controls to? (Choose two.)
PCI DSS
SOC
CSA
ISO
GDPR
Which attack method involves using the same password across multiple external websites and the corporate account, which was compromised due to a data breach?
Remote access Trojan
Brute-force
Dictionary
Credential stuffing
Password spraying
After a natural disaster destroyed an organization's corporate offices, which plan is the organization most likely to consult when setting up offices in a temporary work space?
The business continuity plan
The risk management plan
The communication plan
The incident response plan
