Font size
WorksheetsCySA Review 7 & 8
Total questions: 21
Worksheet time: 11mins
George gathered forensics from a recent intrusion in preparation for legal proceedings. He used EnCase to gather the digital forensics, cloned the hard drive, and took the hard drive home for further analysis. Which of the following did he violate?
Clone procedures
Chain of Command
Chain of Custody
Hashing procedures
George identified 3 Mycc computers that are infected with malware and Windows Defender was unable to detect it. Where is the BEST place to acquire evidence to perform data carving?
Registry
Hard Drive
Memory
Control panel
What would you use to verify that a disk image you created has not been altered
Nessus
Hash
TPM
MD2020
Which four phases outline the procedures involved in a forensics investigation? (select four)
Identification
Collection
Verifying
Analysis
Reporting
To preserve evidence of a temporary file system mounted to a host, which system device must you target for evidence collection?
RAM
HDD
SSD
USB
During an incident response, George obtained evidence from the hard drive of a hacked server. What should he do to ensure the data integrity of the evidence?
Complete Chain of Custody doc
Create hashes for each file on the drive
Encrypt it with AES
Don’t worry about it
What is the first thing that needs to be done when starting an investigation into a cyber security event?
Cry
Secure crime scene
Interview witnesses
Call the police
Process of extracting data (file) out of undifferentiated blocks (raw data)
Carving
Extracting
Enumeration
Exfiltration
George has been alerted to several emails that show evidence an employee is planning malicious activities that involve employee PII on the network before leaving the organization. George's BEST response would be to coordinate with the legal department and:
The police
HR
PR
Nobody
Which of the following would MOST likely be included in the incident response procedure after a security breach of customer PII?
Marketing
HR
PR
SOC
During an incident response procedure, a security analyst collects a hard drive to analyze a possible vector of compromise. There is a Linux swap partition on the hard drive that needs to be checked. Which of the following should the analyst use to extract human-readable content from the partition?
Head
Dd
Strings
fsstat
What would be the best metric for your cyber response team to focus on given recent implementations of SIEM and a ticketing software?
Mean time to detect
Skill of hackers
Mean time to recover
Backup log
This is the time it takes to control, remediate and/or eradicate a threat once it has been discovered.
MTTF
MTTR
MTTD
MMSA
What would George's cybersecurity team do after a security incident to improve incident response in the future?
Schedule a review with everyone to discuss what occurred
Write executive summary for management
Review compliance with PR
Call all impacted users
What would be a good way to begin preparing to create a report titled 'What We Have Learned' in regard to a recent cybersecurity incident involving a breach?
Just worry about the facts
Determine the sophistication of the audience that the report is meant to be viewed by
Determine fonts and color schemes for effectiveness
Develop Table of Contents first
George is worried about the impact of performing vulnerability scans on his company's ICS. What type of scan should be used to minimize the risk of ICS (Industrial Control Systems) devices malfunctioning due to the vulnerability process?
Passive
Agentless
Agent based
Non credentialed
Controls firmware downgrades by software instructions that blow a transistor on hardware chip
TPM
Trusted Execution
eFuse
SED
Solution that manages mobile devices such as remote wipe, device encryption, GPS location, and application controls
MPD
MPG
MDM
MGM
Uses a media encryption key (MEK) to encrypt data and stores the MEK securely by encrypting it with a key encryption key (KEK) generated from the user password.
SED
SLA
Boot guard
Secure enclave
George is required to ensure that the chips and other hardware components in the switches and routers that he purchases do not include any malware. What type of supplier should he seek out?
A TPM
Flea market
A trusted foundry
A gray-market provider
George Inc is developing a vulnerability scanner program for a large network of sensors that are used to monitor his company's transcontinental oil pipeline. What type of network is this?
CAN
SoC
SCADA
BAS
