NEW
Font size
WorksheetsCISSP Module 7
Total questions: 26
Worksheet time: 13mins
What is the purpose of testing Disaster Recovery Plans?
To ensure the effectiveness of recovery strategies
To manage physical security
To address personnel safety concerns
To participate in change management processes
What must be provided by the prosecuting attorneys to prove an individual's guilt beyond a reasonable doubt?
A) A confession
B) Sufficient evidence
C) A witness testimony
D) A motive
Which of the following is NOT one of the basic requirements for evidence to be considered admissible in court?
A) The evidence must be relevant to determine a fact
B) The evidence must be related to the case
C) The evidence must be obtained legally
D) The evidence must be presented by the defense attorney
What are the three types of evidence that can be used in a court of law?
Real Evidence, Documentary Evidence, Testimonial Evidence
Physical Evidence, Written Evidence, Oral Evidence
Best Evidence, Parol Evidence, Real Evidence
Original Evidence, Copy Evidence, Verbal Evidence
What does Parol Evidence refer to?
Originals used (not copies)
Any agreement in writing that can not be changed by a verbal agreement afterwards
Copies used (not originals)
Verbal agreement that changes written agreement
Who should undertake the collection of digital evidence?
Any individual with basic computer knowledge
Professional forensic technicians
Law enforcement officers only
IT support staff
When analyzing digital evidence, what is it best to work with whenever possible?
A copy of actual evidence
The original evidence
A summary of the evidence
A verbal description of the evidence
What must every investigation result in?
A) A verbal report
B) A final report documenting the goals, evidence collected, procedures followed, and final results
C) An informal discussion
D) A summary email
What factors determine the degree of formality behind an investigation report?
A) The investigator's personal preference
B) The organization's policy and procedures and the nature of the investigation
C) The time of year
D) The location of the investigation
Why is it important to prepare formal documentation for an investigation?
A) It is a legal requirement in all cases
B) It lays the foundation for escalation and potential legal action
C) It is easier to share with colleagues
D) It saves time in the long run
What is the primary reason attackers transform their attack methods continually?
To improve their coding skills
To bypass detection and prevention systems
To create new software
To help organizations improve their security
What do organizations typically implement to detect and prevent attacks?
Firewalls and Antivirus Software
Intrusion Detection Systems (IDSs) and Intrusion Prevention Systems (IPSs)
Encryption and Decryption Tools
Password Managers and VPNs
What additional capability does an Intrusion Prevention System (IPS) have compared to an Intrusion Detection System (IDS)?
It can detect malware
It can take additional steps to prevent intrusions
It can monitor network traffic
It can perform data backups
Which of the following is NOT a capability of an IDS?
Detecting DoS and DDoS attacks
Identifying attacks from external links
Providing a timely and accurate response to intrusions
Encrypting data to prevent unauthorized access
What does SIEM stand for?
Security Information and Event Management
System Information and Event Management
Security Information and Event Monitoring
System Information and Event Monitoring
What is one of the primary functions of a SIEM?
Real-time monitoring of traffic and analysis
Data encryption
User authentication
Network routing
On what basis can a SIEM raise alerts and/or trigger responses?
Preconfigured rules
User input
Random selection
Network speed
Which of the following is NOT a common method used to prevent data exfiltration?
Using data loss prevention techniques
Using watermarking
Encrypting data before sending it out
Looking for steganography attempts
What can prevent some standard tools from detecting data exfiltration?
Using data loss prevention techniques
Using watermarking
Encrypting data
Looking for steganography attempts
Why is it important to understand that monitoring is a continuous process?
It helps in automating the review of logs
It ensures all events are recorded and can be investigated later
It helps reconstruct events, provide evidence for prosecution, and create reports for analysis
It increases logging in response to incidents
What is Configuration Management (CM)?
A) A process for managing financial resources
B) A systems engineering process for building and maintaining a product's performance, functional, and physical characteristics
C) A method for software development
D) A technique for marketing management
Which of the following tools is NOT mentioned as being used in Configuration Management?
A) Ansible
B) Puppet
C) Terraform
D) GitHub
What is a potential consequence of a single engineer forgetting to update a piece of software without automation?
The software will run faster.
The system will have an older version of the software with a known vulnerability.
The software will become more secure.
The system will automatically update itself.
Configuration management often applies to which of the following systems?
Servers
Databases and other storage systems
Operating systems
All of the above
What does SaaS stand for?
Software-as-a-service
System-as-a-service
Security-as-a-service
Storage-as-a-service
Why is it important to manage configuration changes carefully?
To increase the speed of the system.
To ensure traceability and prevent data breaches, outages, and data leaks.
To reduce the number of employees.
To increase the complexity of the system.
