NEW
Font size
WorksheetsCySA+Sy Test 04
Total questions: 43
Worksheet time: 22mins
Peter is designing a vulnerability scanning program for the large chain of retail stores where he works. The store operates point-of-sale terminals in its retail stores as well as an e-commerce website. Which one of the following statements about PCI DSS compliance is not true?
Peter’s company must hire an approved scanning vendor to perform vulnerability scans.
The scanning program must include, at a minimum, weekly scans of the internal
network.
The point-of-
sale
terminals and website both require vulnerability scans.
Peter may perform some required vulnerability scans on his own.
Rachel discovered the vulnerability shown here when scanning a web server in her organization.
Which one of the following approaches would best resolve this issue?
Patching the server
Performing input validation
Adjusting firewall rules
Rewriting the application code
What nmap feature is enabled with the -O flag?
OS detection
Online/offline detection
Origami attack detection
Origination port validation
Jose is working with his manager to implement a vulnerability management program for his company. His manager tells him that he should focus on remediating critical and high-severity risks to externally accessible systems. He also tells Jose that the organization does not want to address risks on systems without any external exposure or risks rated medium or lower. Jose disagrees with this approach and believes that he should also address critical and high-severity risks on internal systems. How should he handle the situation?
Jose should recognize that his manager has made a decision based upon the organization’s
risk appetite and should accept it and carry out his manager’s request.
Jose should discuss his opinion with his manager and request that the remediation criteria
be changed.
Jose should ask his manager’s supervisor for a meeting to discuss his concerns about the
manager’s approach.
Jose should carry out the remediation program in the manner that he feels is appropriate
because it will address all of the risks identified by the manager as well as additional
risks.
Susan needs to test thousands of submitted binaries. She needs to ensure that the applications do not contain malicious code. What technique is best suited to this need?
Sandboxing
Implementing a honeypot
Decompiling and analyzing the application code
Fagan testing
When conducting a quantitative risk assessment, what term describes the total amount of damage expected to occur as a result of one incident?
EF
SLE
AV
ALE
Rhonda recently configured new vulnerability scans for her organization’s datacenter. Completing the scans according to current specifications requires that they run all day, every day. After the first day of scanning, Rhonda received complaints from administrators of network congestion during peak business hours. How should Rhonda handle this situation?
Adjust the scanning frequency to avoid scanning during peak times.
Request that network administrators increase available bandwidth to accommodate
scanning.
Inform the administrators of the importance of scanning and ask them to adjust the
business requirements.
Ignore the request because it does not meet security objectives.
After restoring a system from 30-day-old backups after a compromise, administrators at Piper’s company return the system to service. Shortly after that, Piper detects similar signs of compromise again. Why is restoring a system from a backup problematic in many cases?
Backups cannot be tested for security issues.
Restoring from backup may reintroduce the original vulnerability.
Backups are performed with the firewall off and are insecure after restoration.
Backups cannot be properly secured.
Captured network traffic from a compromised system shows it reaching out to a series of five remote IP addresses that change on a regular basis. Since the system is believed to be compromised, the system’s Internet access is blocked, and the system is isolated to a quarantine VLAN.
When forensic investigators review the system, no evidence of malware is found. Which of the following scenarios is most likely?
The system was not infected, and the detection was a false positive.
The beaconing behavior was part of a web bug.
The beaconing behavior was due to a misconfigured application.
The malware removed itself after losing network connectivity.
Which one of the following ISO standards provides guidance on the development and implementation of information security management systems?
ISO 27001
ISO 9000
ISO 11120
ISO 23270
Mika’s forensic examination of a compromised Linux system is focused on determining what level of access attackers may have achieved using a compromised www account. Which of the following is not useful if she wants to check for elevated privileges associated with the www user?
/etc/passwd
/etc/shadow
/etc/sudoers
/etc/group
Tracy is validating the web application security controls used by her organization. She wants to ensure that the organization is prepared to conduct forensic investigations of future security incidents. Which one of the following OWASP control categories is most likely to contribute to this effort?
Implement logging.
Validate all inputs.
Parameterize queries.
Error and exception handling.
Jamal is using agent-based scanning to assess the security of his environment. Every time that Jamal runs a vulnerability scan against a particular system, it causes the system to hang. He spoke with the system administrator, who provided him with a report showing that the
system is current with patches and has a properly configured firewall that allows access from only a small set of trusted internal servers. Jamal and the server administrator both consulted the vendor, and they are unable to determine the cause of the crashes and suspect that it may be a side effect of the agent. What would be Jamal’s most appropriate course of action?
Approve an exception for this server.
Continue scanning the server each day.
Require that the issue be corrected in 14 days and then resume scanning.
Decommission the server.
During an nmap port scan using the -sV flag to determine service versions, Ling discovers that the version of SSH on the Linux system she is scanning is not up-to-date. When she asks the system administrators, they inform her that the system is fully patched and that the SSH version is current. What issue is Ling most likely experiencing?
The system administrators are incorrect.
The nmap version identification is using the banner to determine the service version.
nmap does not provide service version information, so Ling cannot determine version
levels in this way.
The systems have not been rebooted since they were patched.
Tyler scans his organization’s mail server for vulnerabilities and finds the result shown here.
What should be his next step?
Shut down the server immediately.
Initiate the change management process.
Apply the patch.
Rerun the scan.
Carla is performing a penetration test of a web application and would like to use a software package that allows her to modify requests being sent from her system to a remote web server. Which one of the following tools would not meet Carla’s needs?
Nessus
Burp Suite
Zed Attack Proxy (ZAP)
Tamper Data
Alex learns that a recent Microsoft patch covers a zero-day exploit in Microsoft Office that occurs because of incorrect memory handling. The flaw is described as potentially resulting in memory corruption and arbitrary code execution in the context of the current privilege level. Exploitation of the flaws can occur if victims open a specifically crafted Office document in a vulnerable version of Microsoft Office.
If Alex finds out that approximately 15 of the workstations in his organization have been compromised by this malware, including one workstation belonging to a domain administrator, what phase of the incident response process should he enter next?
Preparation
Detection and analysis
Containment, eradication, and recovery
Postincident activity
Maria wants to use a security benchmark that is widely used throughout the industry to baseline her systems as part of a hardening process. Which of the following organizations provides a set of freely available benchmarks for operating systems?
The Center for Internet Security
CompTIA
PCI SSC
OWASP
Sally’s organization wants to prioritize their vulnerability remediation efforts. Which of the following items is not typically critical to prioritization of remediation efforts?
A list of affected hosts
The risk score of the vulnerability
The vulnerability’s name or CVE
The organization or individual that discovered the vulnerability
Chris is reviewing network flow data from systems in his organization and notices that a number of the systems are contacting a remote IP address periodically through the day. He suspects the systems may be compromised. What type of behavior is he most likely seeing?
Data exfiltration
Port scans
Beaconing
Rogue devices
What concern may drive organizations to communicate with customers impacted by a breach within a specific timeline?
Regulatory compliance
Media awareness
Social media interaction
Police involvement
Yuri wants to check if an IP address is known to be malicious. Which of the following options is the most useful way for him to manually check current information about an IP address or hostname?
The SANS Top 20
AbuseIPDB
WHOIS
Cuckoo Sandbox
Carla’s organization is a managed security provider that uses the ITIL, and Carla wants to determine if her team is meeting the service level agreements her organization has agreed to meet for their customers for vulnerability management notifications happening within 24 hours. What is Carla attempting to assess?
A VMO
A SLO
An NDA
A VMS
Joanna’s organization has been performing a forensic investigation of a compromised system. Her team’s analysis indicates that a number of commonly available tools were used by the attacker and that the attacker was using basic, rather than advanced skills and techniques. What type of threat actor is Joanna most likely dealing with?
A hacktivist
A nation-state
actor
A script kiddie
Organized crime
Michelle wants to provide metrics for her security team’s incident response capabilities.
Which of the following is not a common measure for teams like hers?
Mean time to detect
Mean time to respond
Mean time to remediate
Mean time to compromise
Tony is working with information from a closed-source threat feed and combines the feed information with his own organization’s vulnerability management data and asset databases. What activity is Tony performing?
IoC analysis
Geolocation
Active defense
Data enrichment
Which of the following is not a common inhibitor to remediation of vulnerabilities?
Legacy systems
Organizational policies
The potential to degrade functionality
Organizational governance processes
Greg wants to assess the confidence levels for his threat intelligence data. What three common items are most frequently used to determine confidence in threat intelligence?
Timeliness, source quality, and cost
Accuracy, threat actor, and likelihood
Timeliness, relevance, and accuracy
Accuracy, source quality, and cost
Valerie’s incident response process includes moving a compromise system to a separate
VLAN that retains access to the Internet but does not allow contact with other systems on
her network. What containment process has she implemented?
Segmentation
IoC-based
response
Isolation
Sanitization
Isaac wants to view network traffic from a potentially compromised Linux machine. What
tool can he use from the command line to view and analyze his network traffic?
Wireshark
tcpdump
Ettercap
cat /dev/eth0
Isaac wants to view network traffic from a potentially compromised Linux machine. What
tool can he use from the command line to view and analyze his network traffic?
Wireshark
tcpdump
Ettercap
cat /dev/eth0
Beena wants to ensure that her vulnerability management program is performing as expected.
What technique should she use to look at its performance over time so she can see if she has
problematic behaviors or practices?
A regularly created list of the top 10 most common vulnerabilities
A report showing remediation and patching trends
A list of zero-day
vulnerabilities and the time to remediate them
A list of service level objectives
Valentine is reviewing network flow logs and sees a 30 GB data transfer between a database
server and a system outside of her organization. For reviews, how should she flag the event?
Potential data exfiltration
Potential use of unauthorized privileges
A potential malicious process
Potential high drive capacity consumption
Selah wants to use appropriate metrics to determine how well her incident response process is working. Which of the following metrics is not commonly used to assess incident response processes?
Mean time to remediate
Meant time to detect
Mean time to respond
Mean time to defend
Gary wants to use NTP to help with his log analysis efforts. What is Gary doing?
Setting appropriate logging levels
Removing unnecessary logs using a trust process
Time synchronization
Validating log entries against the originals
Nathan’s organization has been notified that there is a vulnerability in a legacy system that does not have vendor support. Nathan needs to ensure that the system is not compromised due to the vulnerability. What should Nathan implement to address this issue?
A patching plan
A compensating control
A remediation plan
An alternate patch
The endpoint detection and response (EDR) system that Li’s organization uses has detected Windows workstations communicating between each other on the network on port 8944.
What should Li flag this traffic as?
Beaconing
A port scan
Unexpected bandwidth consumption
Irregular peer-to-
peer
communication
What phase of incident response needs to happen before customer communications can occur?
Perform stakeholder identification.
Document lessons learned.
Prepare a timeline.
Conduct a root-cause
analysis.
Jake wants to ensure that only authorized IP addresses can send email on behalf of his organization but doesn’t want to require certificates and signatures for the validation. What should he implement?
DKIM
DMARC
S/MIME
SPF
Katie has been reviewing her organization’s vulnerability management reports and notices that systems that are part of a cloud-hosted cluster continue to show a recurring issue where vulnerabilities re-appear
when the cluster is scaled up to handle higher loads. What is the most likely issue that Katie should ask the system administrators about?
Reinstallation of the same software package instead of a patched version
A lack of update to the original cluster image
Patches failing to install
A compromise restoring the system to a vulnerable state
What open source intelligence source is accessible only using a TOR enabled browser or system?
Social media
The Dark Web
Blogs
Government bulletins
Bob’s organization wants to adopt passwordless authentication. What will they need to provide
to users to adopt this solution?
PINs
Biometric identifiers
Hardware tokens
New passwords
Hillary is working on improving her organization’s security response processes and wants to integrate security tools from multiple vendors together. What type of integration should she look for to optimize the ability for systems to work together and exchange data?
FTP-based
integration
Data scraping from built-in
web pages
API-based
integration
A single pane of glass design
