Font size
WorksheetsCybersecurity Core Functions-QUIZ
Total questions: 27
Worksheet time: 17mins
RESPONSE: What are the key steps in an effective response plan?
Identify the threat, assess the impact, develop a strategy, implement the plan, review and revise
Identify the threat, plan for impact, develop a strategy, implement the plan, review and revise
Identify the threat, assess the impact, develop a strategy, implement the plan
Identify the threat, assess the impact, develop a strategy, plan, review and revise
IDENTITY: The five core functions of the NIST Cybersecurity Framework are:
Prepare, Prevent, Respond, Mitigate, Restore
Identify, Protect, Detect, Respond, Recover
Plan, Execute, Monitor, Control, Close
Assess, Implement, Evaluate, Report, Improve
The purpose of a risk assessment in the Identify function is to:
Identify potential risks and vulnerabilities.
Identify who is responsible
Recover from security breaches.
Respond to security incidents.
PROTECT: What are the key security measures in the Protect function of NIST?
Access Control, Awareness and Training, Data Security, Information Protection Processes and Procedures, Maintenance, and Protective Technology
Risk Assessment, Risk Management Strategy, Supply Chain Risk Management
Protecting from Anomalies and Events, through Continuous Monitoring, Detection Processes
Response Planning, Communications, Analysis, Mitigation, Improvements
IDENTIFY: Why is asset management critical in the Identify function of NIST?
Asset management helps in identifying and managing cybersecurity risks to systems, people, assets, data, and capabilities.
Asset management is critical to the Recovery function of NIST.
Asset management only deals with allocating financial assets properly
Asset management is only about maintaining an monitoring the inventory of assets.
The purpose of forensic analysis in the response process is to:
usually useless to solving the problem
Identify the cause of a security breach
improve the ability to repel a similar future attack
Improve the time it takes to shutdown a network.
The primary goal of the Detect function in the NIST framework is to:
Identify cybersecurity events in a timely manner
Protect data from unauthorized access
Respond to detected cybersecurity events
Recover from cybersecurity incidents
PROTECT: How does multi-factor authentication (MFA) contribute to the Protect function?
By requiring biometric scans
By providing an additional layer of security
By frustrating the attacker
By eliminating the need for passwords
Continuous monitoring is important for cybersecurity because:
it helps in early detection of threats and vulnerabilities.
it reduces the need for cybersecurity professionals.
it eliminates all cyber threats.
it is a regulatory requirement only.
RESPONSE: Why is it important to have a pre-defined communication plan in the Respond function?
To allow for spontaneous decision-making
To ensure clear and efficient communication during a response
To increase the number of communication channels
To reduce the need for training
DETECT: What type of tools are commonly used in the Detect function?
Network monitoring tools
Data analysis tools
Communication tools
Project management tools
PROTECT: The role of security awareness training in the Protect function is to:
Enhance staff skills in identifying a hacking attempt
Improve social engineering attempts
Educate employees on security best practices
Increase software efficiency
The main activities in the Recover function of NIST are:
Detecting and monitoring bad hombres
Implementing security measures
Planning and improving resilience and recovery
Conducting regular audits
RECOVER: A business continuity plan is important in cybersecurity recovery because it:
ensures that critical business functions continue during and after a disaster.
focuses solely on preventing cyber attacks.
eliminates the need for cybersecurity measures.
is only necessary for large corporations.
Lessons that should be learned from a cybersecurity incident recovery include:
Social Engineering is the number one reason for coporate data loss.
Improving security protocols
Training on how to respond to a cyber incident is vital to sucess.
Continuous Training staff to identify social engineering patterns is a skill worth learning
which three elements of a phishing attempt are correct
Urgency
threat of access loss if you don't act
bad breath
Your a winner!
unsolicited email
from another country
Tells you to pick up your clothes
unusual time to receive an email
demanding tone
asks you to update your personal infomation
threatens loss of access if you don't act
requests you to click or open an attachment
What is an Intrusion Detection System (IDS) used for?
Blocking malware in emails
Detecting and monitoring suspicious network activity
Creating backup copies of data
Preventing unauthorized software downloads
Why are data backups important in cybersecurity?
They prevent cyberattacks from happening
They allow recovery of lost or encrypted data after a cyberattack
They make sharing sensitive data safer
hey are only useful for legal compliance
What is the NIST and ED Law 2d standard for employee access to sensitive data?
Education level determines access to sensitive data.
The level of sensitive data access is strictly determined by required job duties
Access to sensitive data is determined by Department Heads
Access to sensitive data access should be determined based on every possible scenario I may need
What role does a Security Information and Event Management (SIEM) system play?
Get it right and gain 10 points!
(a)
What is business continuity planning (BCP)? Get it right and get 10 points!
(a)
What is the purpose of an incident response plan?
(a)
What is endpoint security?
(a)
What should be included in an incident report?
Type of vulnerability
what happened
why it happened
whose in trouble
Type of incident, affected systems, timeline, actions taken, and recommendations
The people involved
The amount of money paid
The time we were down
The lost revenue
Type of Incident
affected people
actions considered
people contacted
What is the difference between a vulnerability and a threat?
Get it right get 10 points!
(a)
What is behavioral analysis in cybersecurity?
A process for scheduling system updates
A subtle way to train employees on company policies
A systematic process of randomly sampling network user activity for anomalies
A software/Hardware that can detect when a user or device is acting outside standard benchmarks
What is the purpose of a risk assessment?
To identify critical finance platforms, assess and report on corporate ability to repel and recover from a cyber attack
To keep the auditors happy and off my back
To assess and protect critical business platfroms with a super backup solution
To determine where a corporations risk is and steps they can take to mitigate those risks
