wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CySA+ Days 7 & 8

Total questions: 36

Worksheet time: 18mins

Name
Class
Date
1.

A record of a problem reported by a user or detected by a system is known as a (blank).

a)

Requirement

b)

Incident

c)

Trouble Ticket

d)

IT issue

2.

This term refers to a security event that compromises the Confidentiality, Integrity, or Availability of an information system.

a)

Trouble Ticket

b)

Breach

c)

Incident

d)

Change Request

3.

What is a forensic image?

a)
A forensic image is a type of digital camera used in investigations.
b)
A forensic image is a physical photograph taken at a crime scene.
c)
A forensic image is a complete, exact copy of a digital storage device used for forensic analysis.
d)
A forensic image is a software program for data recovery.
4.

What must you do prior to collecting forensic evidence during an incident response?

a)

Establish a Chain of Custody

b)

Obtain Authorization or Consent

c)

Create a bit-by-bit copy of the storage device

d)

Obtain a tamper-evident bag & seal

5.

What can a forensic investigator perform periodically to safeguard the collected data against any accidental or intentional alterations during the investigation process?

a)

Seal it in a tamper-evident bag

b)

Store it in a secure location

c)

Maintain a proper Chain of Custody

d)

Conduct a Data Integrity Check

6.

Which technique can be used to provide a way to verify the authenticity and integrity of data during forensic investigations?

a)

Use tamper tape

b)

Store it in a secure location

c)

Digitally sign a copy of it

d)

Sprinkle salt on some hash browns

7.

What is the best way a forensic investigator can validate the integrity of a physical device during an incident response?

a)

Use tamper-evident seals

b)

Store it in a secure foot locker

c)

Keep it in a personal safe

d)

Keep it under 24/7 surveillance

8.

Which Preservation technique involves making a bit-for-bit copy of an entire storage device?

a)

Snapshot

b)

Backup

c)

Disk Image

d)

Hash the disk

9.

Which term describes assessing an incident to understand its severity and impact on the organization?

a)
incident evaluation
b)
incident reporting
c)

incident analysis

d)

triage

10.

True or False? Removing the root cause of an incident happens in the Containment phase of Incident Response.

a)

True!

b)

False!

11.

This term describes a pre-defined, step-by-step guide for responding to specific types of incidents, and can even be automated using a SOAR solution.

a)
Incident response plan
b)
Incident management strategy
c)

Playbook

d)

SOP

12.

BC or DR? Describes the efforts the organization takes to keep the organization running during and after a disaster event.

a)

BC

b)

DR

13.

BC or DR? Focuses on the immediate needs of a disaster when things are the most frantic and pressing.

a)

DR

b)

BC

14.

What is the first step in the incident response process?

a)

Identify the problem

b)

Gather information

c)

Establish a Theory

d)

Preparation

15.

These meetings must avoid pointing blame and instead focus on improving procedure.

a)

Tabletop Exercise

b)

Simulation

c)

Lessons Learned

d)

Establish a Theory

16.

Unusual network traffic, system anomalies, unexpected file changes, malware signatures and login anomalies are all examples of ?

a)

Incidents

b)

IoCs

c)

Threats

d)

Unauthorized access attempts

17.

Alvin received an alert from an IDS in the network, and it indicated a severity level of 1. Should he respond immediately or focus on more severe threats first, to ensure proper utilization of resources?

a)

Respond immediately! All hands on deck, Captain Bryan!

b)

A rating of "1" isn't that bad... focus on the others first!

18.

Which tool does a SOAR solution utilize to interact with other security tools and systems seamlessly?

a)

SIEM

b)

VPN

c)

SSH

d)

API

19.

A cybersecurity analyst noticed a potential network breach, so she immediately called the Incident Response team on his VoIP phone. What did she do wrong?

a)

She didn't analyze the data first.

b)

Nothing! Sounds like a timely response to me.

c)

She potentially tipped off the attacker.

d)

Her first response should have been to take steps to halt the incident's progression prior to making phone calls.

20.

If a law firm wanted to ensure the preservation of digital evidence for a case, what would they likely implement?

a)

Chain of Custody

b)

Legal Hold

c)

Preservation Request

d)

Lawful Hold

21.

This document shows each person who had access to the evidence, the actions they took, and the date/time that they accessed it.

a)

Legal Hold

b)

Evidence Document

c)

Chain of Custody

d)

Custody Agreement

22.

This term describes the process of restoring a system to its original state by wiping it clean and installing a fresh OS, along with any applications the end user may need.

a)

Restore (system defaults)

b)

Reimage

c)

Remote Wipe

d)

Disk Image

23.

What is the purpose of Containment?

a)

Isolate

b)

Prevent spread

c)

Segment

d)

Air gap

24.

What is the last step of the digital forensics process?

a)

Legal Hold

b)

Securely store the evidence

c)

Lessons Learned

d)

Reporting

25.

What's the best option of the following tools that can be used to determine the sequence of events of an incident?

a)

Event logs

b)

SIEM report

c)

Timeline

d)

Timestamps

26.

What term describes matching an incident to a specific threat actor or group?

a)

Identification

b)

Threat Profiling

c)

Attribution

d)

Blame

27.

True or False? A company recently experienced a massive data breach. The Public Relations representative did a great job at managing the fallout from the breach, showing that the company is resilient. The way it was handled will likely give the company a competitive advantage.

a)

True

b)

False

28.

Choose the greatest benefit of engaging with the media to manage public perception.

a)

Promotes the company's services

b)

Controls the narrative of a negative situation

c)

Increases brand awareness

d)

Reassures the public that the company is legitimate

29.

True or False? New incidents should be escalated to the relevant personnel who have the authority to address it.

a)

False

b)

True

30.

When dealing with GDPR customers, how many hours would a company have before they must notify them of a breach?

a)

24

b)

72

c)

60 days

d)

48

31.

If criminal activity may have taken place in your organization, what should you do first?

a)

Ask the incident response team to conduct an initial assessment

b)

Notify law enforcement

c)

Seek legal counsel

d)

Notify relevant stakeholders

32.

There was a recent PHI breach that affected 750 employees. How long does the company have before they must contact the US Department of Health and Human Services (HHS)?

a)

72 hours

b)

30 days

c)

60 days

d)

End of the calendar year

33.

In the context of CySA+, MTTR stands for the following (choose 3).

a)

Mean Time To Recover

b)

Mean Time To Respond

c)

Mean Time To Remediate

d)

Mean Time To Repair

34.

Which of the following is a brief overview of a larger report?

a)

Executive Summary

b)

Outline

c)

Executive Series

d)

Lessons Learned

35.

This term describes the quantity of alerts generated by security monitoring tools.

a)

Alert Tuning

b)

Alert Volume

c)

Alert Monitoring

d)

Alert Frequency

36.

Choose the benefit of Root Cause Analysis.

a)

Holistic understanding

b)

Risk Exposure

c)

Problem identification

d)

Symptom identification