WorksheetsDay 12 Quiz - Exploring Scripting Tools, Analysis concepts .....
Total questions: 25
Worksheet time: 20mins
Objective 1.3/Day 12 -
A security analyst is investigating a series of suspicious network requests that appear to be encoded and embedded within an XML file. To analyze the structure and content of these requests, which of the following tools or techniques should the analyst use?
PowerShell
Regular expressions
Python
XML parsing
Objective 1.3/Day 12 -
During an incident response, an analyst discovers a PowerShell script that contains obfuscated commands used to execute malicious payloads. To effectively analyze and understand the script, which tool or technique would be most appropriate?
JSON decoding
Shell script analysis
Python scripting
PowerShell analysis
Objective 1.3/Day 12 -
A security team is reviewing logs that contain entries formatted in JSON. To identify patterns or extract specific information from these logs, which of the following techniques would be most effective?
Python scripting
Regular expressions
XML parsing
PowerShell
Objective 1.3/Day 12 -
An analyst needs to detect and analyze potentially harmful regular expressions embedded within shell scripts. Which of the following approaches would be most effective in this scenario?
Regular expression analysis
Shell script execution
PowerShell scripting
XML parsing
Objective 2.4/Day 12 -
A web application is susceptible to reflected cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts into URLs that are subsequently executed in users' browsers. What control should the development team implement to mitigate this type of vulnerability?
Input validation and sanitization
Implementing a Content Security Policy (CSP)
Using secure cookies
Session management practices
Objective 2.4/Day 12 -
An organization has identified that its application is vulnerable to stack overflow vulnerabilities, which could allow attackers to execute arbitrary code. Which control should be recommended to mitigate the risk associated with this type of vulnerability?
Input validation
Implementing address space layout randomization (ASLR)
Data encryption
Regular security training for developers
Objective 2.4/Day 12 -
A security analyst discovers that an application is vulnerable to data poisoning attacks, where attackers can manipulate input data to compromise the integrity of the application. Which control should be recommended to mitigate this risk?
Implementing rate limiting
Data validation and sanitization
Role-based access control (RBAC)
Logging and monitoring
Objective 2.4/Day 12 -
A recent security audit revealed broken access control vulnerabilities in a web application, allowing users to access resources and functionalities they should not be able to. What control should be recommended to address this issue?
Input validation
Session management practices
Implementing proper authorization checks
Using HTTPS for data transmission
Objective 2.4/Day 12 -
A security analyst has discovered that an application is susceptible to cryptographic failures, specifically due to the use of weak encryption algorithms. Which control should be recommended to mitigate the risk associated with this vulnerability?
Implementing strong encryption standards such as AES
Using hash functions for all sensitive data
Limiting user input to prevent injection attacks
Regularly updating software dependencies
Objective 2.4/Day 12 -
A web application is vulnerable to SQL injection attacks, allowing attackers to manipulate database queries through user inputs. What control should be implemented to mitigate the risk of injection flaws in this application?
Input validation and parameterized queries
Session management practices
Implementing a Content Security Policy (CSP)
Data encryption in transit
Objective 2.4/Day 12 -
During a security review, a vulnerability related to cross-site request forgery (CSRF) is identified in a web application that allows unauthorized actions to be performed on behalf of authenticated users. Which control should be recommended to mitigate this type of vulnerability?
Using SameSite cookies
Implementing input validation
Utilizing encryption for data storage
Restricting access based on IP address
Objective 2.4/Day 12 -
A company has recently discovered that its web application is vulnerable due to insecure design practices, allowing attackers to bypass security controls easily. What control should be implemented to mitigate the risk associated with insecure design?
Conduct regular security reviews and threat modeling
Apply patches to outdated software components
Implement multi-factor authentication (MFA)
Configure firewalls to block unauthorized access
Objective 2.4/Day 12 -
During a routine security audit, it was found that several servers were not configured securely, leaving them exposed to potential attacks. Which control should be recommended to mitigate risks associated with security misconfiguration?
Perform regular configuration audits and hardening
Update the operating system to the latest version
Increase network bandwidth for better performance
Use weak passwords to allow easier access
Objective 2.4/Day 12 -
An organization is still using a legacy application that has reached its end-of-life and is no longer supported by the vendor. What control should be recommended to mitigate risks associated with using outdated components?
Upgrade to a newer, supported version of the application
Implement additional firewalls around the legacy application
Increase user access rights to improve productivity
Disable logging to prevent unnecessary data storage
Objective 2.4/Day 12 -
A web application allows users to submit URLs that the server fetches and processes. An attacker has discovered that they can manipulate the URL to make the server perform requests to internal resources. What control should be implemented to mitigate the risk of Server-Side Request Forgery (SSRF)?
Validate and sanitize user input for URLs
Implement strong access controls on internal resources
Use a web application firewall (WAF)
Regularly update server software and libraries
Objective 2.4/Day 12 -
A security analyst discovers that a web application is vulnerable to Remote Code Execution (RCE) due to inadequate input validation. An attacker can send crafted inputs that allow them to execute arbitrary code on the server. What control should be recommended to mitigate this vulnerability?
Use application-level firewalls
Implement strict input validation and output encoding
Increase logging verbosity for application activities
Limit user access to the application
Objective 2.4/Day 12 -
A user account has been compromised, allowing the attacker to gain higher privileges within the application. The organization needs to mitigate the risk of privilege escalation attacks. Which control should be recommended?
Conduct regular audits of user privileges
Allow users to have admin access for flexibility
Disable two-factor authentication (2FA) for ease of access
Implement a password expiration policy for all users
Objective 1.3/Day 12 -
A security analyst is investigating a suspicious script found on a compromised server. The script is written in PowerShell and contains the following code (See Image):
What is the primary purpose of this PowerShell script?
To update system files
To download and execute a malicious payload
To create a backup of important files
To monitor network traffic
Objective 1.3/Day 12 -
An analyst discovers a Python script running on an internal server. The script's purpose is unclear, so they review the following snippet (See Image):
What does this Python script do?
It updates the system configuration files
It scans a directory and computes the SHA-256 hash of each file
It monitors network traffic
It deletes temporary files in the directory
Objective 2.4/Day 12 -
A web application is vulnerable to cross-site scripting (XSS) attacks where malicious scripts are reflected back to the user. This has led to several incidents of data theft from user sessions. Which control would be most effective in mitigating this type of attack?
Implementing input validation and output encoding
Using secure cryptographic algorithms
Disabling unused services and ports
Applying principle of least privilege to user accounts
Objective 2.4/Day 12 -
A server was compromised through a buffer overflow vulnerability, allowing attackers to execute arbitrary code. Which control is most appropriate to prevent buffer overflow attacks?
Using parameterized queries
Implementing data execution prevention (DEP)
Enforcing multi-factor authentication (MFA)
Conducting regular vulnerability scans
Objective 2.4/Day 12 -
An application allows for unrestricted file uploads, leading to a remote file inclusion (RFI) vulnerability being exploited. Which control should be implemented to mitigate this vulnerability?
Enforcing strict file type validation and scanning uploaded files for malware
Implementing HTTPS across the application
Enforcing password complexity requirements
Disabling directory browsing on the web server
Objective 2.4/Day 12 -
A web application is susceptible to SQL injection attacks, which has allowed attackers to manipulate the database and extract sensitive information. Which control would best mitigate this type of attack?
Implementing input validation and parameterized queries
Encrypting sensitive data at rest
Disabling directory indexing
Using a web application firewall (WAF)
Objective 2.4/Day 12 -
A company's web application has a vulnerability that allows unauthorized users to access restricted directories and files through directory traversal attacks. Which control would most effectively mitigate this vulnerability?
Implementing access control lists (ACLs) and input validation
Using strong encryption for data in transit
Enforcing password expiration policies
Implementing secure session management
Objective 2.4/Day 12 -
An organization has identified several outdated components in its web application stack, which are vulnerable to remote code execution (RCE) attacks. Which control is most appropriate to address this issue?
Regularly updating and patching software components
Implementing network segmentation
Enforcing multi-factor authentication (MFA)
Conducting regular security awareness training
