WorksheetsIAS EXAM v2
Total questions: 148
Worksheet time: 1hrs 14mins
A vendor sells a particular operating system (OS). In order to deploy the OS securely on different platforms, the vendor publishes several sets of instructions on how to install it, depending on which platform the customer is using. This is an example of ______.
Law
Procedure
Standard
Policy
The city of Grampon wants to know where all its public vehicles (garbage trucks, police cars, etc.) are at all times, so the city has GPS transmitters installed in all the vehicles. What kind of control is this?
Administrative
Entrenched
Physical
Technical
Triffid Corporation has a rule that all employees working with sensitive hardcopy documents must put the documents into a safe at the end of the workday, where they are locked up until the following workday. What kind of control is the process of putting the documents into the safe?
Administrative
Tangential
Physical
Technical
Grampon municipal code requires that all companies that operate within city limits will have a set of processes to ensure employees are safe while working with hazardous materials. Triffid Corporation creates a checklist of activities employees must follow while working with hazardous materials inside Grampon city limits. The municipal code is a ______, and the Triffid checklist is a ________.
Law, procedure
Standard, law
Law, standard
Policy, standard
Policy, law
Tina is an (ISC)² member and is invited to join an online group of IT security enthusiasts. After attending a few online sessions, Tina learns that some participants in the group are sharing malware with each other, in order to use it against other organizations online. What should Tina do?
Nothing
Stop participating in the group
Report the group to law enforcement
Report the group to (ISC)2
A bollard is a post set securely in the ground in order to prevent a vehicle from entering an area or driving past a certain point. Bollards are an example of ______ controls.
Physical
Administrative
Drastic
Technical
Triffid Corporation has a policy that all employees must receive security awareness instruction before using email; the company wants to make employees aware of potential phishing attempts that the employees might receive via email. What kind of control is this instruction?
Administrative
Finite
Physical
Technical
The Triffid Corporation publishes a strategic overview of the company's intent to secure all the data the company possesses. This document is signed by Triffid senior management. What kind of document is this?
Policy
Procedure
Standard
Law
Chad is a security practitioner tasked with ensuring that the information on the organization's public website is not changed by anyone outside the organization. This task is an example of ensuring _________.
Confidentiality
Integrity
Availability
Confirmation
The city of Grampon wants to ensure that all of its citizens are protected from malware, so the city council creates a rule that anyone caught creating and launching malware within the city limits will receive a fine and go to jail. What kind of rule is this?
Policy
Procedure
Standard
Law
Zarma is an (ISC)² member and a security analyst for Triffid Corporation. One of Zarma's colleagues is interested in getting an (ISC)2 certification and asks Zarma what the test questions are like. What should Zarma do?
Inform (ISC)2
Explain the style and format of the questions, but no detail
Inform the colleague's supervisor
Nothing
Druna is a security practitioner tasked with ensuring that laptops are not stolen from the organization's offices. Which sort of security control would probably be best for this purpose?
Technical
Observe
Physical
Administrative
For which of the following assets is integrity probably the most important security aspect?
One frame of a streaming video
The file that contains passwords used to authenticate users
The color scheme of a marketing website
Software that checks the spelling of product descriptions for a retail website
Jengi is setting up security for a home network. Jengi decides to configure MAC address filtering on the router, so that only specific devices will be allowed to join the network. This is an example of a(n)_______ control.
Physical
Administrative
Substantial
Technical
Siobhan is an (ISC)² member who works for Triffid Corporation as a security analyst. Yesterday, Siobhan got a parking ticket while shopping after work. What should Siobhan do?
Inform (ISC)2
Pay the parking ticket
Inform supervisors at Triffid
Resign employment from Triffid
Hoshi is an (ISC)² member who works for the Triffid Corporation as a data manager. Triffid needs a new firewall solution, and Hoshi is asked to recommend a product for Triffid to acquire and implement. Hoshi's cousin works for a firewall vendor; that vendor happens to make the best firewall available. What should Hoshi do?
Recommend a different vendor/product
Recommend the cousin's product
Hoshi should ask to be recused from the task
Disclose the relationship, but recommend the vendor/product
Of the following, which would probably not be considered a threat?
Natural disaster
Unintentional damage to the system cause by a user
A laptop with sensitive data on it
An external attacker trying to gain unauthorized access to the environment
Sophia is visiting Las Vegas and decides to put a bet on a particular number on a roulette wheel. This is an example of _________.
Acceptance
Avoidance
Mitigation
Transference
In risk management concepts, a(n) ___________ is something or someone that poses risk to an organization or asset.
Fear
Threat
Control
Asset
Who approves the incident response policy?
(ISC)2
Senior management
The security manager
Investor
When should a business continuity plan (BCP) be activated?
As soon as possible
At the very beginning of a disaster
When senior management decides
When instructed to do so by regulators
True or False? Business continuity planning is a reactive procedure that restores business operations after a disruption occurs.
True
False
What is the goal of an incident response effort?
No incident ever happen
Reduce the impact of incidents on operations
Punish wrongdoers
Save money
What is the risk associated with delaying resumption of full normal operations after a disaster?
People might be put in danger
The impact of running alternate operations for extended periods
A new disaster might emerge
Competition
You are reviewing log data from a router; there is an entry that shows a user sent traffic through the router at 11:45 am, local time, yesterday. This is an example of a(n) _______.
Incident
Event
Attack
Threat
Which of the following are not typically involved in incident detection?
Users
Security analysts
Automated tools
Regulators
Prachi works as a database administrator for Triffid, Inc. Prachi is allowed to add or delete users, but is not allowed to read or modify the data in the database itself. When Prachi logs onto the system, an access control list (ACL) checks to determine which permissions Prachi has.
In this situation, what is the database?
The object
The rule
The subject
The site
Gelbi is a Technical Support analyst for Triffid, Inc. Gelbi sometimes is required to install or remove software. Which of the following could be used to describe Gelbi's account?
Privileged
Internal
External
User
A human guard monitoring a hidden camera could be considered a ______ control.
Detective
Preventive
Deterrent
Logical
In order for a biometric security to function properly, an authorized person's physiological data must be ______.
Broadcast
Stored
Deleted
Modified
A _____ is a record of something that has occurred.
Biometric
Law
Log
Firewall
Trina and Doug both work at Triffid, Inc. Doug is having trouble logging into the network. Trina offers to log in for Doug, using Trina's credentials, so that Doug can get some work done.
What is the problem with this?
Doug is a bad person
If Trina logs in for Doug, then Doug will never be encouraged to remember credential without assistance
Anything either of them do will be attributed to Trina
It is against the law
Which of the following is a biometric access control mechanism?
A badge reader
A copper key
A fence with razor on it
A door locked by a voiceprint identifier
Which of the following statements is true?
Logical access controls can protect the IT environment perfectly; there is no reason to deploy any other controls.
Physical access controls can protect the IT environment perfectly; there is no reason to deploy any other controls.
Administrative access controls can protect the IT environment perfectly; there is no reason to deploy any other controls.
It is best to use a blend of controls in order to provide optimum security.
Which of the following would be considered a logical access control?
An iris reader that allows an employee to enter a controlled area.
A fingerprint reader that allows an employee to enter a controlled area.
A fingerprint reader that allows an employee to access a laptop computer.
A chain attached to a laptop computer that connects it to furniture so it cannot be taken.
Which of the following is probably most useful at the perimeter of a property?
A safe
A fence
A data center
A centralized log storage facility
Handel is a senior manager at Triffid, Inc., and is in charge of implementing a new access control scheme for the company. Handel wants to ensure that employees who are assigned to new positions in the company do not retain whatever access they had in their old positions. Which method should Handel select?
Role-based access controls (RBAC)
Mandatory access controls (MAC)
Discretionary access controls (DAC)
Logging
Prina is a database manager. Prina is allowed to add new users to the database, remove current users and create new usage functions for the users. Prina is not allowed to read the data in the fields of the database itself. This is an example of:
Role-based access controls (RBAC)
Mandatory access controls (MAC)
Discretionary access controls (DAC)
Alleviating threat access controls (ATAC)
Gary is unable to log in to the production environment. Gary tries three times and is then locked out of trying again for one hour. Why?
Gary is being punished
The network is tired
Users remember their credentials if they are given time to think about it
Gary's actions look like an attack
Larry and Fern both work in the data center. In order to enter the data center to begin their workday, they must both present their own keys (which are different) to the key reader, before the door to the data center opens.
Which security concept is being applied in this situation?
Defense in depth
Segregation of duties
Least privilege
Dual control
Prachi works as a database administrator for Triffid, Inc. Prachi is allowed to add or delete users, but is not allowed to read or modify the data in the database itself. When Prachi logs onto the system, an access control list (ACL) checks to determine which permissions Prachi has.
In this situation, what is Prachi?
The subject
The rule
The file
The object
Tekila works for a government agency. All data in the agency is assigned a particular sensitivity level, called a "classification." Every person in the agency is assigned a "clearance" level, which determines the classification of data each person can access.
What is the access control model being implemented in Tekila's agency?
MAC (mandatory access control)
DAC (discretionary access control)
RBAC (role-based access control
FAC (formal access control)
Guillermo logs onto a system and opens a document file. In this example, Guillermo is:
The subject
The object
The process
The software
A tool that monitors local devices to reduce potential threats from hostile software.
NIDS (network-based intrusion-detection systems
Anti-malware
DLP (data loss prevention)
Firewall
Inbound traffic from an external source seems to indicate much higher rates of communication than normal, to the point where the internal systems might be overwhelmed. Which security solution can often identify and potentially counter this risk?
Firewall
Turnstile
Anti-malware
Badge system
Ludwig is a security analyst at Triffid, Inc. Ludwig notices network traffic that might indicate an attack designed to affect the availability of the environment. Which of the following might be the attack Ludwig sees?
DDOS (distributed denial of service)
Spoofing
Exfiltrating stolen data
An insider sabotaging the power supply
Gary is an attacker. Gary is able to get access to the communication wire between Dauphine's machine and Linda's machine and can then surveil the traffic between the two when they're communicating. What kind of attack is this?
Side channel
DDOS
On-path
Physical
A VLAN is a _____ method of segmenting networks.
Secret
Physical
Regulated
Logical
Triffid, Inc., has deployed anti-malware solutions across its internal IT environment. What is an additional task necessary to ensure this control will function properly?
Pay all employees a bonus for allowing anti-malware solutions to be run on their systems
Update the anti-malware solution regularly
Install a monitoring solution to check the anti-malware solution
Alert the public that this protective measure has been taken
Cyril wants to ensure all the devices on his company's internal IT environment are properly synchronized. Which of the following protocols would aid in this effort?
FTP (File Transfer Protocol)
NTP (Network Time Protocol)
SMTP (Simple Mail Transfer Protocol)
HTTP (Hypertext Transfer Protocol)
Barry wants to upload a series of files to a web-based storage service, so that people Barry has granted authorization can retrieve these files. Which of the following would be Barry's preferred communication protocol if he wanted this activity to be efficient and secure?
SMTP (Simple Mail Transfer Protocol)
FTP (File Transfer Protocol)
SFTP (Secure File Transfer Protocol)
SNMP (Simple Network Management Protocol)
The common term for systems that ensure proper temperature and humidity in the data center.
RBAC
HVAC
MAC
A device typically accessed by multiple users, often intended for a single purpose, such as managing email or web pages.
Router
Switch
Server
Laptop
A tool that filters inbound traffic to reduce potential threats.
NIDS (network-based intrusions-detection systems)
Anti-malware
DLP (data loss prevention)
Firewall
Which of the following is one of the common ways potential attacks are often identified?
The attackers contact the target prior to the attack, in order to threaten and frighten the target
Victims notice excessive heat coming from their systems
The power utility company warns customers that the grid will be down, and the internet won't be accessible
Users report unusual systems activity/response to Help Desk or the security office
A device that is commonly useful to have on the perimeter between two networks.
User laptop
IoT
Camera
Firewall
Bert wants to add a flashlight capability to a smartphone. Bert searches the internet for a free flashlight app, and downloads it to the phone. The app allows Bert to use the phone as a flashlight, but also steals Bert's contacts list. What kind of app is this?
DDOS
Trojan
Side channel
On-path
To adequately ensure availability for a data center, it is best to plan for both resilience and _______ of the elements in the facility.
Uniqueness
Destruction
Redundancy
Hue
Which common cloud service model only offers the customer access to a given application?
Lunch as a service (LaaS)
Infrastructure as a service (IaaS)
Platform as a service (PaaS)
Software as a service (SaaS)
A means to allow remote users to have secure access to the internal IT environment.
Internet
VLAN
MAC
VPN
Proper alignment of security policy and business goals within the organization is important because:
Security should always be as strict as possible
Security policy that conflicts with business goals can inhibit productivity
Bad security policy can be illegal
Security is more important than business
If two people want to use asymmetric communication to conduct a confidential conversation, how many keys do they need?
1
4
8
11
Hashing is often used to provide _______.
Confidentiality
Integrity
Availability
Value
One of the benefits of computer-based training (CBT):
Expensive
Scalable
Personal interaction with instructor
Interacting with other participants
Bluga works for Triffid, Inc. as a security analyst. Bluga wants to send a message to several people and wants the recipients to know that the message definitely came from Bluga. What type of encryption should Bluga use?
Symmetric encryption
Asymmetric encryption
Small-scale encryption
Hashing
The output of any given hashing algorithm is always _____.
The same length
The same characters
The same language
Different for the same inputs
Who dictates policy?
The security manager
The Human Resource office
Senior management
Auditors
Triffid, Inc., wants to host streaming video files for the company's remote users, but wants to ensure the data is protected while it's streaming. Which of the following methods are probably best for this purpose?
Symmetric encryption
Hashing
Asymmetric encryption
VLANs
Which of these is the most important reason to conduct security instruction for all employees.
Reduce liability
Provide due diligence
It is a moral imperative
An informed user is a more secure user
______ is used to ensure that configuration management activities are effective and enforced.
Inventory
Baseline
Identification
Verification and audit
If two people want to use symmetric encryption to conduct a confidential conversation, how many keys do they need?
1
3
8
None
Which of the following is probably the main purpose of configuration management?
Keeping out intruders
Ensuring the organization adheres to privacy laws
Keeping secret material protected
Ensuring only authorized are made to the IT environment
The organization should keep a copy of every signed Acceptable Use Policy (AUP) on file, and issue a copy to _______.
The user who signed it
The regulators overseeing that industry
Lawmakers
The Public Relations office
Phrenal is selling a used laptop in an online auction. Phrenal has estimated the value of the laptop to be $100, but has seen other laptops of similar type and quality sell for both more and less than that amount. Phrenal hopes that the laptop will sell for $100 or more, but is prepared to take less for it if nobody bids that amount. This is an example of ___________.
Risk tolerance
Risk inversion
Threat
Vulnerability
Kerpak works in the security office of a medium-sized entertainment company. Kerpak is asked to assess a particular threat, and he suggests that the best way to counter this threat would be to purchase and implement a particular security solution. This is an example of _______.
Acceptance
Avoidance
Mitigation
Transference
Which of the following is an example of a "something you are" authentication factor?
A credit card presented to a cash machine
Your password and PIN
A user ID
A photograph of your face
The Payment Card Industry (PCI) Council is a committee made up of representatives from major credit card providers (Visa, Mastercard, American Express) in the United States. The PCI Council issues rules that merchants must follow if the merchants choose to accept payment via credit card. These rules describe best practices for securing credit card processing technology, activities for securing credit card information, and how to protect customers' personal data. This set of rules is a _____.
Law
Policy
Standard
Procedure
A system that collects transactional information and stores it in a record in order to show which users performed which actions is an example of providing ________.
Non-repudiation
Multifactor authentication
Biometrics
Privacy
Within the organization, who can identify risk?
The security manager
Any security team member
Senior management
Anyone
Glen is an (ISC)² member. Glen receives an email from a company offering a set of answers for an (ISC)² certification exam. What should Glen do?
Nothing
Inform (ISC)²
Inform law enforcement
Inform Glen's employer
Olaf is a member of (ISC)² and a security analyst for Triffid Corporation. During an audit, Olaf is asked whether Triffid is currently following a particular security practice. Olaf knows that Triffid is not adhering to that standard in that particular situation, but that saying this to the auditors will reflect poorly on Triffid. What should Olaf do?
Tell the auditors the truth
Ask supervisors for guidance
Ask (ISC)2 for guidance
Lie to the auditors
The European Union (EU) law that grants legal protections to individual human privacy.
The Privacy Human Rights Act
The General Data Protection Regulation
The Magna Carta
The Constitution
Aphrodite is a member of (ISC)² and a data analyst for Triffid Corporation. While Aphrodite is reviewing user log data, Aphrodite discovers that another Triffid employee is violating the acceptable use policy and watching streaming videos during work hours. What should Aphrodite do?
Inform (ISC)2
Inform law enforcement
Inform Triffid management
Nothing
A software firewall is an application that runs on a device and prevents specific types of traffic from entering that device. This is a type of ________ control.
Physical
Administrative
Passive
Technical
Steve is a security practitioner assigned to come up with a protective measure for ensuring cars don't collide with pedestrians. What is probably the most effective type of control for this task?
Administrative
Technical
Physical
Nuanced
Which of the following probably poses the most risk?
A high-likelihood, high-impact event
A high-likelihood, low-impact event
A low-likelihood, high-impact event
A low-likelihood, low-impact event
(ISC)² publishes a Common Body of Knowledge (CBK) that IT security practitioners should be familiar with; this is recognized throughout the industry as a set of material that is useful for practitioners to refer to. Certifications can be issued for demonstrating expertise in this Common Body of Knowledge. What kind of document is the Common Body of Knowledge?
Policy
Procedure.
Standard
Law
The Triffid Corporation publishes a policy that states all personnel will act in a manner that protects health and human safety. The security office is tasked with writing a detailed set of processes on how employees should wear protective gear such as hardhats and gloves when in hazardous areas. This detailed set of processes is a _________.
Policy
Procedure
Standard
Law
For which of the following systems would the security concept of availability probably be most important?
Medical systems that store patient data
Retail records of past transactions
Online streaming of camera feeds that display historical works of art in museums around the world.
Medical systems that monitor patient condition in an intensive care unit
Preenka works at an airport. There are red lines painted on the ground next to the runway; Preenka has been instructed that nobody can step or drive across a red line unless they request, and get specific permission from, the control tower. This is an example of a(n)______ control.
Physical
Administrative
Critical
Technical
In risk management concepts, a(n) _________ is something a security practitioner might need to protect.
Vulnerability
Asset
Threat
Likelihood
Triffid Corporation has a rule that all employees working with sensitive hardcopy documents must put the documents into a safe at the end of the workday, where they are locked up until the following workday. What kind of control is the process of putting the documents into the safe?
Administrative
Tangential
Physical
Technical
What is the most important goal of a business continuity effort?
Ensure all IT systems function during a potential interruption
Ensure all business activities are preserved during a potential disaster
Ensure the organization survives a disaster
Preserve health and human safety
What is the risk associated with resuming full normal operations too soon after a DR effort?
The danger posed by the disaster might still be present
Investors might be upset
Regulators might disapprove
The organization could save money
All of the following are important ways to practice an organization disaster recovery (DR) effort; which one is the most important?
Practice restoring data from backups
Facility evacuation drills
Desktop/tabletop testing of the plan
Running the alternate operating site to determine if it could handle critical function in time of emergency
Which of the following is likely to be included in the business continuity plan?
Alternate work areas for personnel affected by a natural disaster
The organization's approach security approach
Last year's budget information
Log data from all systems
What is the overall objective of a disaster recovery (DR) effort?
Save money
Return to normal, full operations
Preserve critical business functions during a disaster
Enhance public perception of the organization
An attacker outside the organization attempts to gain access to the organization's internal files. This is an example of a(n) ______.
Intrusion
Exploit
Disclosure
Publication
What is the goal of Business Continuity efforts?
Save money
Impress customers
Ensure all IT system continue to operate
Keep critical business functions operational
Which of the following will have the most impact on determining the duration of log retention?
Personnel preference
Applicable laws
Industry standards
Types of storage media
Handel is a senior manager at Triffid, Inc., and is in charge of implementing a new access control scheme for the company. Handel wants to ensure that operational managers have the utmost personal choice in determining which employees get access to which systems/data. Which method should Handel select?
Role-based access control (RBAC)
Mandatory access control (MAC)
Discretionary access control (DAC)
Security policy
Which of the following is not an appropriate control to add to privileged accounts?
Increased logging
Multifactor authentication
Increased auditing
Security deposit
Prachi works as a database administrator for Triffid, Inc. Prachi is allowed to add or delete users, but is not allowed to read or modify the data in the database itself. When Prachi logs onto the system, an access control list (ACL) checks to determine which permissions Prachi has.
In this situation, what is the ACL?
The subject
The object
The rule
The firmware
All visitors to a secure facility should be _______.
Fingerprinted
Photographed
Escorted
Required to wear protective equipment
Which of these is an example of a physical access control mechanism?
Software-based firewall at the perimeter of the network
A lock on a door
Network switches that filter according to MAC addresses
A process that requires two people to act at the same time to perform a function
Network traffic originating from outside the organization might be admitted to the internal IT environment or blocked at the perimeter by a ________.
Turnstile
Fence
Vacuum
Firewall
Trina is a security practitioner at Triffid, Inc. Trina has been tasked with selecting a new product to serve as a security control in the environment. After doing some research, Trina selects a particular product. Before that product can be purchased, a manager must review Trina's selection and determine whether to approve the purchase. This is a description of:
Two-person integrity
Segregation of duties
Software
Defense in depth
All of the following are typically perceived as drawbacks to biometric systems, except:
Lack of accuracy
Potential privacy concerns
Retention of physiological data past the point of employment
Legality
Handel is a senior manager at Triffid, Inc., and is in charge of implementing a new access control scheme for the company. Handel wants to ensure that employees transferring from one department to another, getting promoted, or cross-training to new positions can get access to the different assets they'll need for their new positions, in the most efficient manner. Which method should Handel select?
Role-based access control (RBAC)
Mandatory access control (MAC)
Discretionary access control (DAC)
Barbed wire
At Parvi's place of work, the perimeter of the property is surrounded by a fence; there is a gate with a guard at the entrance. All inner doors only admit personnel with badges, and cameras monitor the hallways. Sensitive data and media are kept in safes when not in use.
This is an example of:
Two-person integrity
Segregation of duties
Defense in depth
Penetration testing
Bruce is the branch manager of a bank. Bruce wants to determine which personnel at the branch can get access to systems, and under which conditions they can get access. Which access control methodology would allow Bruce to make this determination?
Mandatory access control (MAC)
Discretionary access control (DAC)
Role-based access control (RBAC)
Defense-in-depth
Visitors to a secure facility need to be controlled. Controls useful for managing visitors include all of the following except:
Sign-in sheet/tracking log
Fence
Badges that differ from employee badges
Receptionist
Suvid works at Triffid, Inc. When Suvid attempts to log in to the production environment, a message appears stating that Suvid has to reset the password. What may have occurred to cause this
Suvid broke the law
Suvid's password has expired
Suvid made the manager angry
Someone hacked Suvid's machine
Prachi works as a database administrator for Triffid, Inc. Prachi is allowed to add or delete users, but is not allowed to read or modify the data in the database itself. When Prachis logs onto the system, an access control list (ACL) checks to determine which permissions Prachi has.
Which security concept is being applied in this situation?
Defense in depth
Layered defense
Two-person integrity
Least privilege
Which of the following roles does not typically require privileged account access?
Security administrator
Data entry professional
System administrator
Help desk technician
What is the access control model being implemented in Tekila's agency?
Mandatory access control (MAC)
Discretionary access control (DAC)
Role-based access control (RBAC)
Formal access control (FAC)
Which of the following is not a typical benefit of cloud computing services?
Reduced cost of ownership/investment
Metered usage
Scalability
Freedom from legal constraints
"Wiring _____" is a common term meaning "a place where wires/conduits are often run, and equipment can be placed, in order to facilitate the use of local networks."
Shelf
Closet
Bracket
House
The section of the IT environment that is closest to the external world; where we locate IT systems that communicate with the Internet.
VLAN
DMZ
MAC
RBAC
Which common cloud service model offers the customer the most control of the cloud environment?
Lunch as a service (LaaS)
Infrastructure as a service (IaaS)
Platform as a service (PaaS)
Software as a service (SaaS)
Which common cloud deployment model typically features only a single customer's data/functionality stored on specific systems/hardware?
Public
Private
Community
Hybrid
An IoT (Internet of Things) device is typified by its effect on or use of the _____ environment.
Philosophical
Remote
Internal
Physical
The logical address of a device connected to the network or Internet.
Media access control (MAC) address
Internet Protocol (IP) address
Geophysical address
Terminal address
A tool that inspects outbound traffic to reduce potential threats.
NIDS (network-based intrusion-detection systems)
Anti-malware
DLP (data loss prevention)
Firewall
Which type of fire-suppression system is typically the safest for humans?
Water
Dirt
Oxygen-depletion
Gaseous
Which of the following activities is usually part of the configuration management process, but is also extremely helpful in countering potential attacks?
Annual budgeting
Conferences with senior leadership
Updating and patching systems
The annual shareholders' systems
The concept that the deployment of multiple types of controls provides better security than using a single type of control.
VPN
Least privilege
Internet
Defense in depth
Cheryl is browsing the Web. Which of the following protocols is she probably using?
SNMP (Simple Network Management Protocol)
FTP (File Transfer Protocol)
TFTP (Trivial File Transfer Protocol)
HTTP (Hypertext Transfer Protocol)
A tool that aggregates log data from multiple sources, and typically analyzes it and reports potential threats.
HIDS
Anti-malware
Router
SIEM
Triffid, Inc., has many remote workers who use their own IT devices to process Triffid's information. The Triffid security team wants to deploy some sort of sensor on user devices in order to recognize and identify potential security issues. Which of the following is probably most appropriate for this specific purpose?
HIDS (host-based intrusion-detection systems)
NIDS (network-based intrusion-detection systems)
LIDS (logistical intrusion-detection systems)
Firewalls
Which type of fire-suppression system is typically the least expensive?
Water
Dirt
Oxygen-depletion
Gaseous
Carol is browsing the Web. Which of the following ports is she probably using?
12
80
247
999
Garfield is a security analyst at Triffid, Inc. Garfield notices that a particular application in the production environment is being copied very quickly, across systems and devices utilized by many users. What kind of attack could this be?
Spoofing
Side channel
Trojan
Worm
Which of the following would be best placed in the DMZ of an IT environment?
User's workplace laptop
Mail server
Database engine
SIEM log storage
When Pritha started working for Triffid, Inc., Pritha had to sign a policy that described how Pritha would be allowed to use Triffid's IT equipment. What policy was this?
The organizational security policy
The acceptable use policy (AUP)
The bring-your-own-device (BYOD) policy
The workplace attire policy
Every document owned by Triffid, Inc., whether hardcopy or electronic, has a clear, 24-point word at the top and bottom. Only three words can be used: "Sensitive," "Proprietary" and "Public."
This is an example of _____.
Secrecy
Privacy
Inverting
Labeling
An organization must always be prepared to ______ when applying a patch.
Pay for the updated content
Buy a new system
Settle lawsuits
Rollback
Security controls on log data should reflect ________.
The organization's commitment to customer service
The local culture where the log data is stored
The price of the storage device
The sensitivity of the source device
Archiving is typically done when _________.
Data is ready to be destroyed
Data has lost all value
Data is not needed for regular work purposes
Data has become illegal
By far, the most crucial element of any security instruction program.
Protect assets
Preserve health and human safety
Ensure availability of IT systems
Preserve shareholder value
Log data should be kept ______.
On the device that the log data was captured from
In an underground bunker
In airtight containers
On a device other than where it was captured
Data _____ is data left behind on systems/media after normal deletion procedures have been attempted.
Fragments
Packets
Remanence
Residue
Data _____ is data left behind on systems/media after normal deletion procedures have been attempted.
Fragments
Packets
Remanence
Residue
Data retention periods apply to ____ data.
Medical
Sensitive
All
Secret
Dieter wants to send a message to Lupa and wants to be sure that Lupa knows the message has not been modified in transit. What technique/tool could Dieter use to assist in this effort?
Hashing
Clockwise rotation
Symmetric encryption
Asymmetric encryption
When data has reached the end of the retention period, it should be _____.
Destroyed
Archived
Enhanced
Sold
Security needs to be provided to ____ data.
Restricted
Illegal
Private
All
Logs should be reviewed ______.
Every Thursday
Continually
Once per calendar
Once per fiscal year
