NEW
Font size
WorksheetsOWASP Noida Quiz
Total questions: 35
Worksheet time: 13mins
What type of control is a policy or procedure?
Directive
Corrective
Detective
Preventive
Murali has deployed a file integrity monitoring tool and has configured alerts to notify him if
files are modified. What control type best describes this solution?
Preventive
Deterrent
Directive
Detective
Valerie wants to authenticate her systems using her AAA system. Which of the following
options is best suited to system authentication?
Asymmetric authentication
Certificate-based authentication
Symmetric authentication
PIN-based authentication
What type of attack depends on the attacker entering JavaScript into a text area that is
intended for users to enter text that will be viewed by other users?
SQL injection
Clickjacking
Cross-site scripting
Bluejacking
Valerie is investigating a recent incident and checks /var/log on a Linux system. She finds
the audit.log file empty despite the system uptime showing over a month of uptime. What
has she most likely encountered?
A wiped log
A recent reboot
A system error
Incorrect permissions to view the log
Which of the following is not a common concern related to the hardware vendor
supply chain?
Malware preinstalled on hardware
Lack of availability of hardware
Third-party hardware modifications
Malicious firmware modifications
Ilya is reviewing logs and notices that one of his staff has logged in from his home location in
China at 2 p.m., and then logged in from the United Kingdom an hour later. What indicator
of compromise should he flag this as?
Concurrent session usage
Resource inaccessibility
Impossible travel
Segmentation
Nick purchases his network devices through a gray market supplier that imports them into
his region without an official relationship with the network device manufacturer. What risk
should Nick identify when he assesses his supply chain risk?
Lack of vendor support
Lack of warranty coverage
Inability to validate the source of the devices
All of the above
The following graphic shows a network connection between two systems, and then a
network-based attack. What type of attack is shown?
A denial-of-service attack
A SQL injection attack
An on-path attack
A directory traversal attack
John is running an IDS on his network. Users sometimes report that the IDS flags legitimate
traffic as an attack. What describes this?
False positive
False negative
False trigger
False flag
George is a network administrator at a power plant. He notices that several turbines had
unusual ramp-ups in cycles last week. After investigating, he finds that an executable was
uploaded to the system control console and caused this. Which of the following would be
most effective in preventing this from affecting the SCADA system in the future?
Implement SDN.
Improve patch management.
Place the SCADA system on a separate VLAN
Implement encrypted data transmissions
Ramon is building a new web service and is considering which parts of the service should use
Transport Layer Security (TLS). Components of the application include:
1. Authentication
2. A payment form
3. User data, including address and shopping cart
4. A user comments and reviews section
Where should he implement TLS?
At points 1 and 2, and 4
At points 2 and 3, and 4
At points 1, 2, and 3
At all points in the infrastructure
Which device would most likely process the following rules?
PERMIT IP ANY EQ 443
DENY IP ANY ANY
NIPS
HIPS
Content filter
Firewall
Jason is considering deploying a network intrusion prevention system (IPS) and wants to be
able to detect advanced persistent threats (APTs). What type of IPS detection method is most
likely to detect the behaviors of an APT after it has gathered baseline information about
normal operations?
Signature-based IPS detections
Heuristic-based IPS detections
Malicious tool hash IPS detections
Anomaly-based IPS detections
Jack wants to ensure that files have not changed. What technique can he use to compare
current versions of the files to an original copy?
Encryption.
Check the file size.
Check the file metadata.
Compare hashes of the files.
Which of the following data types best describes data covered by the European
Union’s GDPR?
Trade secrets
Intellectual property
Regulated data
Legal information
What layer is Layer 7 in the OSI model?
The physical layer
The application layer
The transport layer
The session layer
Brent wants to monitor traffic using an IPS. He needs to prevent attack traffic from impact-
ing his datacenter and wants to minimize the amount of traffic that the IPS device has to
filter. Where should he place the device to best match these requirements based on the
following figure?
Position A
Position B
Position C
Position D
Tristan deploys the network device shown in the following figure. The organization’s web
browsing traffic is directed through it and the traffic is filtered as described in the image.
What type of network appliance is shown?
A web application firewall
A proxy server
A jump server
A load balancer
Jackson is reviewing his organization’s logs and discovers multiple new user accounts cre-
ated after business hours using administrative credentials. What term describes searching for
potential issues like this?
IoC creation
Threat hunting
Root cause analysis
Eradication
CVE is an example of what type of feed?
A threat intelligence feed
A vulnerability feed
A critical infrastructure listing feed
A critical virtualization exploits feed
Carolyn runs a vulnerability scan of a network device and discovers that the device is
running services on TCP ports 22 and 443. What services has she most likely discovered?
Telnet and a web server
FTP and a Windows file share
SSH and a web server
SSH and a Windows file share
Tony wants to implement a biometric system for entry access in his organization. Which of
the following systems is likely to be most accepted by members of his organization’s staff?
Fingerprint
Retina
Iris
Voice
Elizabeth wants to implement a cloud-based authorization system. Which of the following
protocols is she most likely to use for that purpose?
OpenID
Kerberos
SAML
OAuth
What is the primary goal of phishing attacks?
To steal personal information
To access public data
To monitor internet speed
To update software
Which of the following practices is the best defense against social engineering attacks?
Using strong passwords
Avoiding unknown emails and links
Updating antivirus software
Regularly clearing browser cache
When using public Wi-Fi, what precaution should be taken to protect your data?
Avoid connecting to public Wi-Fi
Only use open networks
Use a Virtual Private Network (VPN)
Change device settings frequently
What is a key feature of a strong password?
Only lowercase letters
Personal information included
Mix of letters, numbers, and symbols
Based on a common word
How can you recognize a secure website?
It has a long URL
It begins with "https"
It loads very quickly
It has animated graphics
Which of the following is a method attackers use to trick users into revealing personal information?
Phishing
DNS Spoofing
IP Flooding
Port Scanning
Which of the following is a method attackers use to trick users into revealing personal information?
Phishing
DNS Spoofing
IP Flooding
Port Scanning
What is the purpose of multi-factor authentication (MFA)?
To simplify login process
To increase security by requiring multiple forms of verification
To save login credentials automatically
To log in from multiple devices
What should you do if you receive an unexpected email asking for sensitive information?
Respond quickly to avoid problems
Forward it to your contacts
Delete it immediately without reading
Verify the sender before responding
Which of the following is a common sign of a compromised device?
High battery performance
Faster application loading
Slow performance or unexpected pop-ups
Increased storage space
What should you do with sensitive documents on a shared computer after use?
Leave them open for the next user
Print them for backup
Log out and delete any downloaded files
Rename files for future access
