wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

AP CK CyberSecurity Unit 5

Total questions: 10

Worksheet time: 5mins

Name
Class
Date
1.

Which of the following is a hidden temporary version of a file created when a user accesses that file?

a)

Archived data

b)

Metadata

c)

Encrypted data

d)

Active data

2.

An investigator is responding to a cyber attack. They are evaluating information about a file, including:

Who created the file

When the file was last modified

Who last modified the file

What type of data is the investigator reviewing?

a)

Metadata

b)

Archived data

c)

Residual data

d)

Active data

3.

Which of the following is an example of a host-based indicator of compromise (IoC)?

a)

Suspicious file hashes detected on a recently downloaded file

b)

Unexpected processes or services running

c)

Multiple failed log-in attempts to a system

d)

Unauthorized attempts to access sensitive data

4.

A network administrator is looking into a cyber incident and notices the following discrepancies.

There are numerous failed log-in attempts to a device during the time of the incident

The log-in times for these failed log-ins took place when users were typically not logged on

Once the adversary got into the system, they attempted to elevate their privileges on the system

Which type of indicator of compromise (IoC) was the network administrator investigating?

a)

Host-based IoC

b)

File-based IoC

c)

Behavior-based IoC

d)

Memory-based IoC

5.

Which of the following containment measures is used to help stop a cyber attack from spreading from an infected host to other clean hosts on a network?

a)

Backing up any critical information to a secure location

b)

Disabling Bluetooth and Wi-Fi connections

c)

Implementing multi-factor authentication

d)

Monitoring network traffic for unusual activity

6.

A network technician is working on a device and completes the following steps.

  1. 1)They backup any critical files on a system

  2. 2)They wipe the system clean

  3. 3)They reinstall a fresh operating system

  4. 4)They restore the backed-up files to the device

  5. What is the primary purpose of completing these steps?

a)

They are removing malware from an infected computer

b)

They are creating a test environment for new applications

c)

They are setting up the system for a new user

d)

They are installing software to improve cybersecurity

7.

A network administrator is creating a backup site for an office to prepare for potential future cyber incidents. The backup site must adhere to the following requirements.

The site has utility access, but will need to be turned on in the event of using it

The site is a room with no devices that will need to be set up in case it is needed

The site needs to be a cost effective place to maintain when it is not in use

Which type of backup site is the network administrator setting up?

a)

Hot site

b)

Warm site

c)

Lukewarm site

d)

Cold site

8.

What should organizations consider when implementing redundant systems?

a)

Increased costs against potential risks

b)

Impact on threat detection

c)

The organization's password policy

d)

The tradeoffs of symmetric versus asymmetric cryptography

9.

A system administrator is developing a disaster recovery plan (DRP). The following information is known.

The maximum amount of time a system can be down until it affects the organization

Time based goals for the disaster recovery team for when certain systems need to be brought back up

How to minimize the operational disruption and restore normal business functions in the shortest time possible

What part of the DRP is the system administrator currently creating?

a)

Mean time to repair (MTTR)

b)

Mean time to restore service (MTRS)

c)

Recovery point objective (RPO)

d)

Recovery time objective (RTO)

10.

Which of the following best describes the recovery point objective (RPO)?

a)

The amount of data that can be lost before it negatively impacts an organization

b)

The maximum acceptable downtime before a system must be restored

c)

The maximum number of users affected during a disaster

d)

The minimum level of security necessary for data protection