wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Week 20 Quizzz

Total questions: 15

Worksheet time: 8mins

Name
Class
Date
1.

Gurvinder has been asked to assist a company that recently fired one of their developers. After the developer was terminated, the critical application that they had written for the organization stopped working and now displays a message reading, "You shouldn't have fired me!" If the developer's access was terminated and the organization does not believe that they would have had access to any systems or code after they left the organization, what type of malware should Gurvinder look for?

a)
  • A RAT

b)

A PUP

c)

A logic bomb

d)

A keylogger

2.

Naomi believes that an attacker has compromised a Windows workstation using a fileless malware package. What Windows scripting tool was most likely used to download and execute the malware?

a)
VBScript
b)

Bash

c)

Python

d)
PowerShell
3.

Scott notices that one of the systems on his network contacted a number of systems via encrypted web traffic, downloaded a handful of files, and then uploaded a large amount of data to a remote system. What type of infection should he look for?

a)

A keylogger

b)

A backdoor

c)

A bot

d)

A logic bomb

4.

One of your systems has been infiltrated and a malicious actor has direct access. Which option would be the best to follow initially?

a)

A. Segmentation

b)

B. Isolation

c)

C. Disconnection

d)

D. Quarantine

5.

In a company users are now allowed to user mobile devices on the company network. A screen appears when users are connected to the company Wi-Fi, defining terms of use, and users have to click to acknowledge the agreement. The user is only allowed to connect to the network If he agrees to the terms by clicking Yes. This is an example of what?

a)

A. User acceptance

b)

B. Acceptable use policy

c)

C. Authentication

d)

D. End user license agreement

6.

What works as a neutral zone, separating public-facing servers from sensitive internal network resources?

a)

A. Demilitarized Zone

b)

B. Screen Subnet

c)

C. Firewall Rule

d)

D. HoneyPot

7.

Which of the following is not related to time-based restrictions? (opt any two)

a)

A. Network/Logical Location

b)

B. Logon Hours

c)

C. Temporary Permissions

d)

D. Logon Duration

8.

a friend of yours on a social network sends you a direct message telling you about a scheme offering a $100 gift card if you are one of the first 25 to respond to a survey. Upon clicking the link, you realize a malware has infected your machine. Identify the two attack principles you think have contributed to the effectiveness of this attack? (opt any two)

a)

A. Authority

b)

B. Trust

c)

C. Scarcity

d)

D. Intimidation

9.

When referencing the CIA Triad which component is related to data that is stored and transferred as intended and any modification is authorized?

a)

A. Availability

b)

B. Non-repudiation

c)

C. Confidentiality

d)

D. Integrity

10.

Data types are extremely important when categorizing data and establishing a security plan. Which data type would be related to data that must follow specific legal requirements for storage and handling?

a)

A. Intellectual Property

b)

B. Legal Data

c)

C. Trade Secrets

d)

D. Regulated Data

11.

At a datacenter a user has been challenged by three different authentication methods as visible in the exhibit. Identify the option that BEST describes the multifactor authentication policy in use?

a)

A. The authentication depends on something he knows, something he does, and somewhere he is.

b)

B. The authentication depends on something he has, something he is, and somewhere he is.

c)

C. The authentication depends on something he knows, something he is, and somewhere he is.

d)

D. The authentication depends on something he has, something he does, and somewhere he is.

12.

Risk management is a large part of blue team activities within the cybersecurity space. Which of the following is not one of the four Pillars of risk responses?

a)

A. Avoid

b)

B. Isolate

c)

C. Accept

d)

D. Mitigate

13.

In the process of a server application under development, some errors are discovered to leave the application running in an unstable condition. One such error is a divide by zero error. The application should respond more appropriately to errors including generating error message when they appear. Which of the following would you implement?

a)

A. Application hardening

b)

B. Patch management

c)

C. Exception handling

d)

D. Input validation

14.

About the validation process of vulnerability response and remediation, which step is not apart of this process?

a)

A. Verification

b)

B. Patching

c)

C. Reporting

d)

D. Re-scanning

15.

Which Security Control Functional Type identifies attempted or successful intrusions?

a)

A. Corrective

b)

B. Detective

c)

C. Deterrent

d)

D. Preventative