NEW
Font size
WorksheetsCybersecurity Quiz
Total questions: 60
Worksheet time: 30mins
The board of directors is responsible for which of the following?
Transference
Avoidance
Mitigation
Acknowledgement
A forensic analyst needs to identify the hash value of a disk image. Which of the following is the most appropriate tool to use?
Calculate the checksum
Look for the hash value in the image
Ensure proper procedures for chain of custody are followed
A security manager has to map a network drive. Which of the following commands should be used?
map-p 80 to 10.10.0.2
nslookup 10.10.0.2
pathping 10.10.10.0 -p 80
A security manager has to map a network drive. Which of the following commands should be used?
map-p 80 to 10.10.0.2
Most VDI
Avoidance
Acknowledgement
A help desk technician receives a call from a user who is unable to access a file. Which of the following should the technician do first?
Check the metadata in the file
Hover the mouse over the file
Forward the email to the CIO and ask if the CIO sent it
Which of the following is the best method to prevent a phishing attack?
A visiting email stating a cash settlement has been approved
A phishing email stating a cash settlement has been approved
A phishing email stating a cash settlement has been approved
A phishing email stating a cash settlement has been approved
A security forensic analyst needs to identify the hash value of a disk image. Which of the following is the most appropriate tool to use?
Snapshot
Incremental
Full
The Chief Information Security Officer (CISO) is responsible for which of the following?
Lessons learned
Preparation
Detection
Containment
Which of the following controls is used to prevent unauthorized access to a system?
Preventive
Deterrent
Detective
A security manager has to map a network drive. Which of the following commands should be used?
map-p 80 to 10.10.0.2
nslookup 10.10.0.2
pathping 10.10.10.0 -p 80
A cloud service provider offers a hybrid model. Which of the following is an example of a hybrid model?
Public
Community
Private
A security engineer is building a secure network. Which of the following protocols should be used to encrypt data in transit?
AES
EAP
TLS
A security engineer is building a secure network. Which of the following protocols should be used to encrypt data in transit?
SSH
S/MIME
LDAPS
Which of the following is a data loss prevention (DLP) technique?
DLP
TPM
NIDS
A cloud service provider offers a hybrid model. Which of the following is an example of a hybrid model?
Hybrid VDI
Private VDI
Community VDI
A company discovered that an attacker used a protocol to gain unauthorized access to their network. Which protocol was likely used?
SNMPv3
SFTP
Telnet
Which of the following is a data loss prevention (DLP) technique?
DLP
TPM
FDE
A security engineer is building a secure network. Which of the following protocols should be used to encrypt data in transit?
TLS
EAP
HTTPS
Which of the following is the best method to prevent a phishing attack?
Network segmentation
Patch management
Multiple vulnerability scanners
A security engineer is building a secure network. Which of the following protocols should be used to encrypt data in transit?
AES
HTTPS
TLS
A security analyst wants to test the connectivity to a remote server. Which of the following commands should be used?
curl -head http://192.168.0.1
ping -t 192.168.0.10
Which of the following documents outlines the service levels and expectations between a service provider and a customer?
SLA
EOL
MOU
Multiple business accounts have been compromised. Which of the following is the most likely cause?
Password history
Complexity requirements
Shared accounts
An amusement park is concerned about the security of their ticketing system. Which of the following should be implemented first?
Low FRR
Low FAR
Low efficacy
Low CER
A report from the company's Information Security Office indicates that a system has a false positive. Which of the following is the most likely cause?
False positive
True Negative
False Negative
Which biometric error would allow an unauthorized user to gain access to a system?
False acceptance
False rejection
False denial
A company suspects that an employee is accessing sensitive information without authorization. Which of the following should be implemented to prevent this?
Enforce MFA when an employee logs in
Implement geofencing
Shift the access control scheme to a discretionary access control (DAC) model
Employees who travel need to access the company's network securely. Which of the following should be implemented?
PKI
Blockchain
OAuth
C. SAML partners with which of the following to provide single sign-on (SSO) capabilities?
Blockchain
OAuth
SAML
Several universities are planning to collaborate on a research project. Which of the following cloud deployment models would be most appropriate?
Community
Private
Public
Hybrid
A security analyst is working on a behavior-based detection method. Which of the following is the analyst most likely to use?
Vulnerability scans
User behavior analysis
Security orchestration
Threat hunting
A company discovered an attack that is using a zero-day exploit. Which of the following is the company most likely experiencing?
Insider threat
APT
Script kiddies
Shadow IT
The Chief Compliance Officer (CCO) is concerned about insider threats. Which of the following would be the best method to mitigate this risk?
Filtering applicants who have worked at other banks
Preventing any current employees from working at other banks
Ensuring no new hires have worked at other banks
Ensuring no new hires have worked at other banks that have had insider threats
Which of the following techniques is used to hide the true nature of an attack?
Obfuscation
Normalization
Execution
Reuse
Certain users are reporting issues where workstations are being accessed without their knowledge. Which of the following should be checked to identify the issue?
Endpoint protection
Travel times on logins
Sensitive data is being accessed
All user account passwords
Which of the following attacks uses a program that captures keystrokes?
Keylogger
Brute-force
Dictionary
Rainbow
An organization discovered an attack that is using a program to capture keystrokes. Which of the following is the organization most likely experiencing?
Keylogger
Brute-force
Dictionary
Remote access Trojan
Officers log in to the file server and notice that the system is running slowly. Which of the following is the most likely cause?
Logic bomb
Cryptominer
Spyware
Remote access Trojan
Certain users are reporting issues where workstations are being accessed without their knowledge. Which of the following should be checked to identify the issue?
Endpoint protection
Travel times on logins
Sensitive data is being accessed
All user account passwords
A security analyst is reviewing logs and notices that several accounts have been locked out. Which of the following is the most likely cause?
Keylogger
Brute-force
Dictionary
Rainbow
Which of the following is a type of malware that is designed to gain unauthorized access to a system?
SQL Most Voted
API attack
DLL injection
XSS
A DBA reports that several databases have been compromised. Which of the following is the most likely cause?
Logic bomb
Fileless virus
Remote access Trojan
Rootkit
A security analyst is reviewing logs and notices that several accounts have been locked out. Which of the following is the most likely cause?
SQL injection
XSS attack
XSRF attack
Replay attack
An organization discovered an attack that is using a program to capture keystrokes. Which of the following is the organization most likely experiencing?
Logic bomb
Cryptominer
Spyware
Remote access Trojan
A systems administrator is reviewing logs and notices the following entries: **1244** Timecard.exe **1244** ERROR: SUM **1244** Timecard.exe **1244** malcode: 8211 **1244** Checkfile: 8211 **1244** Checkfile: 8211 The administrator identifies the issue as a buffer overflow. Which of the following is the most likely cause?
DLL injection
API attack
Buffer overflow
Memory leak
An organization discovered an attack that is using a program to capture keystrokes. Which of the following is the organization most likely experiencing?
Logic bomb
Cryptominer
Spyware
Remote access Trojan
An employee received a suspicious email with an attachment. Which of the following is the most likely cause?
Macro-enabled file
Embedded Python code
Bash scripting
Credential-harvesting website
A security analyst is reviewing logs and notices that several accounts have been locked out. Which of the following is the most likely cause?
SQL injection
API attack
DLL injection
XSS
Which of the following is a type of malware that is designed to gain unauthorized access to a system?
Shared Tenancy
Zero-day
Insider Threat
Unsecured root accounts
An organization maintains a development environment for testing new applications. Which of the following is the most likely stage of the environment?
Development
Production
Test
Staging
Which of the following is the most likely stage of the environment where new applications are tested before being moved to production?
Stage
Development
Production
Test
A Chief Security Officer is reviewing the network configuration and notices that several servers are using NIC teaming. Which of the following is the most likely reason for this configuration?
Improved performance
Automated patch management
Snapshots
NIC Teaming
Which of the following is the most likely reason for implementing a GPO?
Putting security controls in place
Installing an endpoint agent to detect connectivity issues
Placing systems into a specific OU
SDN
A company is looking to migrate its infrastructure to the cloud. Which of the following is the most likely model they will use?
SaaS
IaaS
PaaS
SDN
A company is looking to migrate its infrastructure to the cloud. Which of the following is the most likely model they will use?
SaaS
PaaS
IaaS
SDN
A cloud service provider is offering a hybrid model. Which of the following is the most likely reason for this offering?
Public
Community
Private
Hybrid
A security professional is reviewing backup strategies. Which of the following is the most likely type of backup that includes all data?
Snapshot
Differential
Cloud
Full
Which of the following is the most likely stage of the environment where new applications are tested before being moved to production?
Stage
Development
Production
Test
A company is looking to implement a cloud service model that provides virtualized computing resources over the internet. Which model should they choose?
SaaS
IaaS
PaaS
SDN
A company wants to simplify the management of SSL certificates across multiple subdomains. Which type of certificate should they use?
Wildcard
Subject alternative name
Self-signed
Domain validation
