wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

CISSP Module 7

Total questions: 26

Worksheet time: 13mins

Name
Class
Date
1.

What is the purpose of testing Disaster Recovery Plans?

a)

To ensure the effectiveness of recovery strategies

b)

To manage physical security

c)

To address personnel safety concerns

d)

To participate in change management processes

2.

What must be provided by the prosecuting attorneys to prove an individual's guilt beyond a reasonable doubt?

a)

A) A confession

b)

B) Sufficient evidence

c)

C) A witness testimony

d)

D) A motive

3.

Which of the following is NOT one of the basic requirements for evidence to be considered admissible in court?

a)

A) The evidence must be relevant to determine a fact

b)

B) The evidence must be related to the case

c)

C) The evidence must be obtained legally

d)

D) The evidence must be presented by the defense attorney

4.

What are the three types of evidence that can be used in a court of law?

a)

Real Evidence, Documentary Evidence, Testimonial Evidence

b)

Physical Evidence, Written Evidence, Oral Evidence

c)

Best Evidence, Parol Evidence, Real Evidence

d)

Original Evidence, Copy Evidence, Verbal Evidence

5.

What does Parol Evidence refer to?

a)

Originals used (not copies)

b)

Any agreement in writing that can not be changed by a verbal agreement afterwards

c)

Copies used (not originals)

d)

Verbal agreement that changes written agreement

6.

Who should undertake the collection of digital evidence?

a)

Any individual with basic computer knowledge

b)

Professional forensic technicians

c)

Law enforcement officers only

d)

IT support staff

7.

When analyzing digital evidence, what is it best to work with whenever possible?

a)

A copy of actual evidence

b)

The original evidence

c)

A summary of the evidence

d)

A verbal description of the evidence

8.

What must every investigation result in?

a)

A) A verbal report

b)

B) A final report documenting the goals, evidence collected, procedures followed, and final results

c)

C) An informal discussion

d)

D) A summary email

9.

What factors determine the degree of formality behind an investigation report?

a)

A) The investigator's personal preference

b)

B) The organization's policy and procedures and the nature of the investigation

c)

C) The time of year

d)

D) The location of the investigation

10.

Why is it important to prepare formal documentation for an investigation?

a)

A) It is a legal requirement in all cases

b)

B) It lays the foundation for escalation and potential legal action

c)

C) It is easier to share with colleagues

d)

D) It saves time in the long run

11.

What is the primary reason attackers transform their attack methods continually?

a)

To improve their coding skills

b)

To bypass detection and prevention systems

c)

To create new software

d)

To help organizations improve their security

12.

What do organizations typically implement to detect and prevent attacks?

a)

Firewalls and Antivirus Software

b)

Intrusion Detection Systems (IDSs) and Intrusion Prevention Systems (IPSs)

c)

Encryption and Decryption Tools

d)

Password Managers and VPNs

13.

What additional capability does an Intrusion Prevention System (IPS) have compared to an Intrusion Detection System (IDS)?

a)

It can detect malware

b)

It can take additional steps to prevent intrusions

c)

It can monitor network traffic

d)

It can perform data backups

14.

Which of the following is NOT a capability of an IDS?

a)

Detecting DoS and DDoS attacks

b)

Identifying attacks from external links

c)

Providing a timely and accurate response to intrusions

d)

Encrypting data to prevent unauthorized access

15.

What does SIEM stand for?

a)

Security Information and Event Management

b)

System Information and Event Management

c)

Security Information and Event Monitoring

d)

System Information and Event Monitoring

16.

What is one of the primary functions of a SIEM?

a)

Real-time monitoring of traffic and analysis

b)

Data encryption

c)

User authentication

d)

Network routing

17.

On what basis can a SIEM raise alerts and/or trigger responses?

a)

Preconfigured rules

b)

User input

c)

Random selection

d)

Network speed

18.

Which of the following is NOT a common method used to prevent data exfiltration?

a)

Using data loss prevention techniques

b)

Using watermarking

c)

Encrypting data before sending it out

d)

Looking for steganography attempts

19.

What can prevent some standard tools from detecting data exfiltration?

a)

Using data loss prevention techniques

b)

Using watermarking

c)

Encrypting data

d)

Looking for steganography attempts

20.

Why is it important to understand that monitoring is a continuous process?

a)

It helps in automating the review of logs

b)

It ensures all events are recorded and can be investigated later

c)

It helps reconstruct events, provide evidence for prosecution, and create reports for analysis

d)

It increases logging in response to incidents

21.

What is Configuration Management (CM)?

a)

A) A process for managing financial resources

b)

B) A systems engineering process for building and maintaining a product's performance, functional, and physical characteristics

c)

C) A method for software development

d)

D) A technique for marketing management

22.

Which of the following tools is NOT mentioned as being used in Configuration Management?

a)

A) Ansible

b)

B) Puppet

c)

C) Terraform

d)

D) GitHub

23.

What is a potential consequence of a single engineer forgetting to update a piece of software without automation?

a)

The software will run faster.

b)

The system will have an older version of the software with a known vulnerability.

c)

The software will become more secure.

d)

The system will automatically update itself.

24.

Configuration management often applies to which of the following systems?

a)

Servers

b)

Databases and other storage systems

c)

Operating systems

d)

All of the above

25.

What does SaaS stand for?

a)

Software-as-a-service

b)

System-as-a-service

c)

Security-as-a-service

d)

Storage-as-a-service

26.

Why is it important to manage configuration changes carefully?

a)

To increase the speed of the system.

b)

To ensure traceability and prevent data breaches, outages, and data leaks.

c)

To reduce the number of employees.

d)

To increase the complexity of the system.