NEW
Font size
WorksheetsAP CK CyberSecurity Unit 5
Total questions: 10
Worksheet time: 5mins
Which of the following is a hidden temporary version of a file created when a user accesses that file?
Archived data
Metadata
Encrypted data
Active data
An investigator is responding to a cyber attack. They are evaluating information about a file, including:
Who created the file
When the file was last modified
Who last modified the file
What type of data is the investigator reviewing?
Metadata
Archived data
Residual data
Active data
Which of the following is an example of a host-based indicator of compromise (IoC)?
Suspicious file hashes detected on a recently downloaded file
Unexpected processes or services running
Multiple failed log-in attempts to a system
Unauthorized attempts to access sensitive data
A network administrator is looking into a cyber incident and notices the following discrepancies.
There are numerous failed log-in attempts to a device during the time of the incident
The log-in times for these failed log-ins took place when users were typically not logged on
Once the adversary got into the system, they attempted to elevate their privileges on the system
Which type of indicator of compromise (IoC) was the network administrator investigating?
Host-based IoC
File-based IoC
Behavior-based IoC
Memory-based IoC
Which of the following containment measures is used to help stop a cyber attack from spreading from an infected host to other clean hosts on a network?
Backing up any critical information to a secure location
Disabling Bluetooth and Wi-Fi connections
Implementing multi-factor authentication
Monitoring network traffic for unusual activity
A network technician is working on a device and completes the following steps.
1)They backup any critical files on a system
2)They wipe the system clean
3)They reinstall a fresh operating system
4)They restore the backed-up files to the device
What is the primary purpose of completing these steps?
They are removing malware from an infected computer
They are creating a test environment for new applications
They are setting up the system for a new user
They are installing software to improve cybersecurity
A network administrator is creating a backup site for an office to prepare for potential future cyber incidents. The backup site must adhere to the following requirements.
The site has utility access, but will need to be turned on in the event of using it
The site is a room with no devices that will need to be set up in case it is needed
The site needs to be a cost effective place to maintain when it is not in use
Which type of backup site is the network administrator setting up?
Hot site
Warm site
Lukewarm site
Cold site
What should organizations consider when implementing redundant systems?
Increased costs against potential risks
Impact on threat detection
The organization's password policy
The tradeoffs of symmetric versus asymmetric cryptography
A system administrator is developing a disaster recovery plan (DRP). The following information is known.
The maximum amount of time a system can be down until it affects the organization
Time based goals for the disaster recovery team for when certain systems need to be brought back up
How to minimize the operational disruption and restore normal business functions in the shortest time possible
What part of the DRP is the system administrator currently creating?
Mean time to repair (MTTR)
Mean time to restore service (MTRS)
Recovery point objective (RPO)
Recovery time objective (RTO)
Which of the following best describes the recovery point objective (RPO)?
The amount of data that can be lost before it negatively impacts an organization
The maximum acceptable downtime before a system must be restored
The maximum number of users affected during a disaster
The minimum level of security necessary for data protection
