Font size
Worksheets701 Security Plus Mega Challenge 2
Total questions: 17
Worksheet time: 31mins
Match the attacks to the proper name.
Attacker tries common passwords repeatedly on an account until he succeeds.
Brute Force
Any attack that relies on deceiving or manipulation humans.
Social Engineering
An attack that is difficult to detect and is aimed at the memory of a system.
Memory Injection
Attack that plants code into the structure of a website with the intent to steal a victims cookies.
XSS
Attack that manipulates the queries between a web application and a database using a cheat code "1"="1".
SQLi
Identify the attack.
Employee receives text from unknown number asking the employee to purchase a gift card.
Smishing
Hacker gains access to an underlying host by breaking out of a VM.
VM Escape
An attacker socially engineers an employee into giving him valid credentials.
Credential Harvesting
Attacker takes over CEO email and requests financial info in an attempt to trick employees.
Business Email Compromise
Tricking a user into visiting a fake site by mimicking a legitimate URL. ie: www.paypa1.com.
Typosquatting
Order the steps of the incident response process.
Planning/Preparation
Identification
Containment
Eradication
Recovery
Match the following.
Best way to test out or update our Incident Response Plan.
Table Top
Exercise
A conclusive report completed in lessons learned that summarizes the underlying cause of an incident.
Root Cause Analysis
A step-by-step guide that tells an incident response team how to respond to an incident.
Playbook
The phase in the incident response plan where reports are generated.
Lessons Learned
The phase of the incident response process that isolates a threat to minimize operational impact.
Containment
Match the situation with the risk mitigation technique being used.
Mark purchased Cyber Insurance for ransomware attacks.
Risk Transfer
Daniel decided to keep Windows 10 until Windows 11 bugs and kinks are all worked out.
Risk Avoidance
Keisha decided that there is no way to reduce, avoid, or transfer any remaining risk. She must do this.
Risk Acceptance
Sara placed a lock on a fence to ensure no one can get in.
Risk Reduction
A place where all the organizations risks are documented and maintained.
Risk Register
Match the risk terms to their appropriate definitions.
The amount of risk a company chooses to take on.
Risk Appetite
The amount of risk a company can afford to take on.
Risk Tolerance
Central location where all risk can be observed and assessed.
Risk Dashboard
Method of determining monetary value of risks to determine financial impact. using SLExARO=ALE.
Quantitative Risk Assessment
Method of determining risk factors using LOW, MEDIUM, or HIGH.
Qualitative Risk Assessment
Match the following risk terms.
The amount of monetary loss we can expect from one occurrence.
SLE
The amount of monetary loss we can expect from occurrences that happen over one year.
ALE
The amount of times we can expect an event to occur.
ARO
A formula we use to determine how much we lose annually.
SLE x ARO = ALE
IP Cyber has issued laptops to all employees. Each laptop costs $2000.00. The laptop must be shipped to each employee, costing around $200.00 for shipping fees. The Senior Risk Coordinator has assessed that we have lost 16 laptops in the past 4 years. What is the ALE?
$32,000.00
$35,200.00
$8,000.00
$8,800.00
Match the remediation that counters the attack.
SQLi "1"="1"
Input Validation
The attacker is trying multiple passwords on a user account.
Account Lockout Policy
Accounting has been issuing checks to an unknown bank account.
Update Internal Processes
An attacker convinced an employee to let them through using their access badge, claiming they had forgotten their own.
Social Engineering Training
Sam is worried about an attacked using a rainbow table to break stored hash values.
Salting
Match the coding terms to their definitions.
Henry is creating a program. He should follow this process to ensure it is structurally sound and meets security requirements.
SDLC
Our company wants a refined process where we can combine new code with old code, and get it into the production environment fast.
CI/CD
Darnell needs a place to store different versions of a program he is developing.
Code Repository
This is a traditional way of coding that should be avoided due to its hindrance of modern security applications.
Monolithic Code
This is code in a code structure that is not executed when the program is ran.
Dead Code
Match the following:
Allows for quick identification of malicious file signatures by analyzing stand-still code.
Static Analysis
More comprehensive analysis of code that is conducted while the program is running.
Dynamic Analysis
A development life cycle model that only allows developers to move forward in the development process.
Waterfall Model
A development life cycle model that allows developers to move forward and backward in the development process.
Agile Model
A system that keeps track of different versions of something.
Version Control
Match the following regulations.
Standard that outlines the requirement to implement an ISMS.
ISO 27001
Supporting standard that outlines security control options that can be used in an ISMS.
ISO 27002
Law that governs how companies handle credit/debit card data.
PCI DSS
Standard the outlines how Privacy should be handled when dealing with PII data.
ISO 27701
The "Right to Erasure" law. applies to European Citizens.
GDPR
Match the compliance terms.
The act of researching all laws that apply to your organization.
Due Diligence
Largest concern of non-compliance - incalculable monetary loss.
Reputational Damage
The most common result of being noncompliant.
Fines
Report that shows how effective all security controls have been over a period of time in an organization.
SOC 2 Type II
Lists all security controls in an organization.
SOC 2 Type I
Match the following Compliance/Regulatory terms.
An amount of time specified by the government that regulates how long a company must hold on to certain data types.
Data Retention
A law term that specifies a company must follow laws int he geographical areas it is operating in.
Data Sovereignty
The title of the person in an organization who ensures data retention requirements are met.
Data Custodian
When a company is not following all applicable laws and regulations.
Noncompliance
A preservation order placed on evidence, requiring a company to preserve any and all digital evidence while collection occurs.
Legal Hold
Match the following terms.
The science of collecting evidence from a system.
Digital Forensics
A clause in a contract that allows our company to conduct reviews of our vendors to ensure they meet compliance.
Right to Audit
The process of holding onto digital evidence to ensure it retains integrity.
Preservation
This can be requested to ensure a third-party is meeting all security regulations and laws.
Compliance Attestation Report
Special rules that are placed on a company that is found to be noncompliant.
Sanctions
What is most likely the reason we would need to conduct regular internal audits to ensure we meet all requirements from applicable laws in our organization?
Regulatory Requirements by the Government
Good-Faith Assessments should be regular
Cost-to-Benefit Analysis on company strategies
Because its the right thing to do.
Our company wants to gather information about a potential third party vendor we plan to work with. In order to find out the last time the government audited them, or the last time they were attacked, we should do what?
Submit a Questionnaire
Conduct a Penetration Test
Ask for a 27001 report
Contact the Federal Government for statistics
