wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

701 Security Plus Mega Challenge 2

Total questions: 17

Worksheet time: 31mins

Name
Class
Date
1.

Match the attacks to the proper name.

a)

Attacker tries common passwords repeatedly on an account until he succeeds.

1.

Brute Force

b)

Any attack that relies on deceiving or manipulation humans.

2.

Social Engineering

c)

An attack that is difficult to detect and is aimed at the memory of a system.

3.

Memory Injection

d)

Attack that plants code into the structure of a website with the intent to steal a victims cookies.

4.

XSS

e)

Attack that manipulates the queries between a web application and a database using a cheat code "1"="1".

5.

SQLi

2.

Identify the attack.

a)

Employee receives text from unknown number asking the employee to purchase a gift card.

1.

Smishing

b)

Hacker gains access to an underlying host by breaking out of a VM.

2.

VM Escape

c)

An attacker socially engineers an employee into giving him valid credentials.

3.

Credential Harvesting

d)

Attacker takes over CEO email and requests financial info in an attempt to trick employees.

4.

Business Email Compromise

e)

Tricking a user into visiting a fake site by mimicking a legitimate URL. ie: www.paypa1.com.

5.

Typosquatting

3.

Order the steps of the incident response process.

a)

Planning/Preparation

b)

Identification

c)

Containment

d)

Eradication

e)

Recovery

1)
2)
3)
4)
5)
4.

Match the following.

a)

Best way to test out or update our Incident Response Plan.

1.

Table Top
Exercise

b)

A conclusive report completed in lessons learned that summarizes the underlying cause of an incident.

2.

Root Cause Analysis

c)

A step-by-step guide that tells an incident response team how to respond to an incident.

3.

Playbook

d)

The phase in the incident response plan where reports are generated.

4.

Lessons Learned

e)

The phase of the incident response process that isolates a threat to minimize operational impact.

5.

Containment

5.

Match the situation with the risk mitigation technique being used.

a)

Mark purchased Cyber Insurance for ransomware attacks.

1.

Risk Transfer

b)

Daniel decided to keep Windows 10 until Windows 11 bugs and kinks are all worked out.

2.

Risk Avoidance

c)

Keisha decided that there is no way to reduce, avoid, or transfer any remaining risk. She must do this.

3.

Risk Acceptance

d)

Sara placed a lock on a fence to ensure no one can get in.

4.

Risk Reduction

e)

A place where all the organizations risks are documented and maintained.

5.

Risk Register

6.

Match the risk terms to their appropriate definitions.

a)

The amount of risk a company chooses to take on.

1.

Risk Appetite

b)

The amount of risk a company can afford to take on.

2.

Risk Tolerance

c)

Central location where all risk can be observed and assessed.

3.

Risk Dashboard

d)

Method of determining monetary value of risks to determine financial impact. using SLExARO=ALE.

4.

Quantitative Risk Assessment

e)

Method of determining risk factors using LOW, MEDIUM, or HIGH.

5.

Qualitative Risk Assessment

7.

Match the following risk terms.

a)

The amount of monetary loss we can expect from one occurrence.

1.

SLE

b)

The amount of monetary loss we can expect from occurrences that happen over one year.

2.

ALE

c)

The amount of times we can expect an event to occur.

3.

ARO

d)

A formula we use to determine how much we lose annually.

4.

SLE x ARO = ALE

8.

IP Cyber has issued laptops to all employees. Each laptop costs $2000.00. The laptop must be shipped to each employee, costing around $200.00 for shipping fees. The Senior Risk Coordinator has assessed that we have lost 16 laptops in the past 4 years. What is the ALE?

a)

$32,000.00

b)

$35,200.00

c)

$8,000.00

d)

$8,800.00

9.

Match the remediation that counters the attack.

a)

SQLi "1"="1"

1.

Input Validation

b)

The attacker is trying multiple passwords on a user account.

2.

Account Lockout Policy

c)

Accounting has been issuing checks to an unknown bank account.

3.

Update Internal Processes

d)

An attacker convinced an employee to let them through using their access badge, claiming they had forgotten their own.

4.

Social Engineering Training

e)

Sam is worried about an attacked using a rainbow table to break stored hash values.

5.

Salting

10.

Match the coding terms to their definitions.

a)

Henry is creating a program. He should follow this process to ensure it is structurally sound and meets security requirements.

1.

SDLC

b)

Our company wants a refined process where we can combine new code with old code, and get it into the production environment fast.

2.

CI/CD

c)

Darnell needs a place to store different versions of a program he is developing.

3.

Code Repository

d)

This is a traditional way of coding that should be avoided due to its hindrance of modern security applications.

4.

Monolithic Code

e)

This is code in a code structure that is not executed when the program is ran.

5.

Dead Code

11.

Match the following:

a)

Allows for quick identification of malicious file signatures by analyzing stand-still code.

1.

Static Analysis

b)

More comprehensive analysis of code that is conducted while the program is running.

2.

Dynamic Analysis

c)

A development life cycle model that only allows developers to move forward in the development process.

3.

Waterfall Model

d)

A development life cycle model that allows developers to move forward and backward in the development process.

4.

Agile Model

e)

A system that keeps track of different versions of something.

5.

Version Control

12.

Match the following regulations.

a)

Standard that outlines the requirement to implement an ISMS.

1.

ISO 27001

b)

Supporting standard that outlines security control options that can be used in an ISMS.

2.

ISO 27002

c)

Law that governs how companies handle credit/debit card data.

3.

PCI DSS

d)

Standard the outlines how Privacy should be handled when dealing with PII data.

4.

ISO 27701

e)

The "Right to Erasure" law. applies to European Citizens.

5.

GDPR

13.

Match the compliance terms.

a)

The act of researching all laws that apply to your organization.

1.

Due Diligence

b)

Largest concern of non-compliance - incalculable monetary loss.

2.

Reputational Damage

c)

The most common result of being noncompliant.

3.

Fines

d)

Report that shows how effective all security controls have been over a period of time in an organization.

4.

SOC 2 Type II

e)

Lists all security controls in an organization.

5.

SOC 2 Type I

14.

Match the following Compliance/Regulatory terms.

a)

An amount of time specified by the government that regulates how long a company must hold on to certain data types.

1.

Data Retention

b)

A law term that specifies a company must follow laws int he geographical areas it is operating in.

2.

Data Sovereignty

c)

The title of the person in an organization who ensures data retention requirements are met.

3.

Data Custodian

d)

When a company is not following all applicable laws and regulations.

4.

Noncompliance

e)

A preservation order placed on evidence, requiring a company to preserve any and all digital evidence while collection occurs.

5.

Legal Hold

15.

Match the following terms.

a)

The science of collecting evidence from a system.

1.

Digital Forensics

b)

A clause in a contract that allows our company to conduct reviews of our vendors to ensure they meet compliance.

2.

Right to Audit

c)

The process of holding onto digital evidence to ensure it retains integrity.

3.

Preservation

d)

This can be requested to ensure a third-party is meeting all security regulations and laws.

4.

Compliance Attestation Report

e)

Special rules that are placed on a company that is found to be noncompliant.

5.

Sanctions

16.

What is most likely the reason we would need to conduct regular internal audits to ensure we meet all requirements from applicable laws in our organization?

a)

Regulatory Requirements by the Government

b)

Good-Faith Assessments should be regular

c)

Cost-to-Benefit Analysis on company strategies

d)

Because its the right thing to do.

17.

Our company wants to gather information about a potential third party vendor we plan to work with. In order to find out the last time the government audited them, or the last time they were attacked, we should do what?

a)

Submit a Questionnaire

b)

Conduct a Penetration Test

c)

Ask for a 27001 report

d)

Contact the Federal Government for statistics