wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CySA Review 7 & 8

Total questions: 21

Worksheet time: 11mins

Name
Class
Date
1.

George gathered forensics from a recent intrusion in preparation for legal proceedings. He used EnCase to gather the digital forensics, cloned the hard drive, and took the hard drive home for further analysis. Which of the following did he violate?

a)

Clone procedures

b)

Chain of Command

c)

Chain of Custody

d)

Hashing procedures

2.

George identified 3 Mycc computers that are infected with malware and Windows Defender was unable to detect it. Where is the BEST place to acquire evidence to perform data carving?

a)

Registry

b)

Hard Drive

c)

Memory

d)

Control panel

3.

What would you use to verify that a disk image you created has not been altered

a)

Nessus

b)

Hash

c)

TPM

d)

MD2020

4.

Which four phases outline the procedures involved in a forensics investigation? (select four)

a)

Identification

b)

Collection

c)

Verifying

d)

Analysis

e)

Reporting

5.

To preserve evidence of a temporary file system mounted to a host, which system device must you target for evidence collection?

a)

RAM

b)

HDD

c)

SSD

d)

USB

6.

During an incident response, George obtained evidence from the hard drive of a hacked server. What should he do to ensure the data integrity of the evidence?

a)

Complete Chain of Custody doc

b)

Create hashes for each file on the drive

c)

Encrypt it with AES

d)

Don’t worry about it

7.

What is the first thing that needs to be done when starting an investigation into a cyber security event?

a)

Cry

b)

Secure crime scene

c)

Interview witnesses

d)

Call the police

8.

Process of extracting data (file) out of undifferentiated blocks (raw data)

a)

Carving

b)

Extracting

c)

Enumeration

d)

Exfiltration

9.

George has been alerted to several emails that show evidence an employee is planning malicious activities that involve employee PII on the network before leaving the organization. George's BEST response would be to coordinate with the legal department and:

a)

The police

b)

HR

c)

PR

d)

Nobody

10.

Which of the following would MOST likely be included in the incident response procedure after a security breach of customer PII?

a)

Marketing

b)

HR

c)

PR

d)

SOC

11.

During an incident response procedure, a security analyst collects a hard drive to analyze a possible vector of compromise. There is a Linux swap partition on the hard drive that needs to be checked. Which of the following should the analyst use to extract human-readable content from the partition?

a)

Head

b)

Dd

c)

Strings

d)

fsstat

12.

What would be the best metric for your cyber response team to focus on given recent implementations of SIEM and a ticketing software?

a)

Mean time to detect

b)

Skill of hackers

c)

Mean time to recover

d)

Backup log

13.

This is the time it takes to control, remediate and/or eradicate a threat once it has been discovered.

a)

MTTF

b)

MTTR

c)

MTTD

d)

MMSA

14.

What would George's cybersecurity team do after a security incident to improve incident response in the future?

a)

Schedule a review with everyone to discuss what occurred

b)

Write executive summary for management

c)

Review compliance with PR

d)

Call all impacted users

15.

What would be a good way to begin preparing to create a report titled 'What We Have Learned' in regard to a recent cybersecurity incident involving a breach?

a)

Just worry about the facts

b)

Determine the sophistication of the audience that the report is meant to be viewed by

c)

Determine fonts and color schemes for effectiveness

d)

Develop Table of Contents first

16.

George is worried about the impact of performing vulnerability scans on his company's ICS. What type of scan should be used to minimize the risk of ICS (Industrial Control Systems) devices malfunctioning due to the vulnerability process?

a)

Passive

b)

Agentless

c)

Agent based

d)

Non credentialed

17.

Controls firmware downgrades by software instructions that blow a transistor on hardware chip

a)

TPM

b)

Trusted Execution

c)

eFuse

d)

SED

18.

Solution that manages mobile devices such as remote wipe, device encryption, GPS location, and application controls

a)

MPD

b)

MPG

c)

MDM

d)

MGM

19.

Uses a media encryption key (MEK) to encrypt data and stores the MEK securely by encrypting it with a key encryption key (KEK) generated from the user password.

a)

SED

b)

SLA

c)

Boot guard

d)

Secure enclave

20.

George is required to ensure that the chips and other hardware components in the switches and routers that he purchases do not include any malware. What type of supplier should he seek out?

a)

A TPM

b)

Flea market

c)

A trusted foundry

d)

A gray-market provider

21.

George Inc is developing a vulnerability scanner program for a large network of sensors that are used to monitor his company's transcontinental oil pipeline. What type of network is this?

a)

CAN

b)

SoC

c)

SCADA

d)

BAS