Font size
Worksheets701 Security Plus Mega Challenge 3
Total questions: 13
Worksheet time: 24mins
Match the following.
Your vulnerability scanner did not find any issues, but there are issues on your computer.
False Negative
Your vulnerability scanner found issues, but there actually aren't any issued on your computer.
False Positive
Adjusting the sensitivity of your scanner to reduce false positives.
Rule Tuning
A scan that is performed while logged into the computer with IT Admin credentials.
Credentialed Scan
A scan that is performed while logged into a computer on a user account without IT admin credentials.
Non-Credentialed Scan
Match the tools to their purpose.
A program you can install that will monitor an endpoint for you, and let you know about events that occur.
EDR
A configuration strategy you can use to observe behaviors of users and determine if they are doing anything they shouldn't be doing.
UBA
A program you can install that looks for intrusions and sounds the alarm when it finds one.
IDS
A program you can install that looks for intrusions, and provides an automated response when it finds one.
IPS
Aggregates log data into a timeline for analysis.
SIEM
Match the following terms.
The primary concern of performing this is that it could cause a disruption to operations.
Vulnerability Assessment
This is known as workforce multiplier, and it enhances automation and orchestration.
SIEM
A cryptographic technology that we use to check the integrity of a data structure.
Hash
The best method to use to store credit card and debit card data in a database.
Tokenization
A technique used to hide data in an image file.
Steganography
Answer the following
A new security regulation is released, our company should perform one of these to ensure we can meet it.
Gap Analysis
Company has a critical system they cannot remove. The system is EOL. They should use this.
Isolated VLAN
This is an example of a physical security control.
ACV
We use this to verify the integrity of software that we want to download.
Hashing
We can feed multiple logs into this and it will analyze them for us.
SIEM
Answer the following
We sign one of these with our vendors to ensure they don't release our critical information.
NDA
We can look here to see a list of all computers our computers are talking to.
Firewall logs
Collecting and duplicating digital evidence is known as this.
Acquisition
Tracking the handling of digital evidence is known done on this.
Chain of Custody
Insider threats exfiltrate data using this.
Unidentified Removable Devices
Match the following threat actors to their motivations.
Motivated by personal beliefs
Hacktivist
Motivated by financial gain
Criminal
Motivated by intelligence/information
State Actor
Motivated by revenge
Insider Threat
A threat actor whose goal is residence
APT
Answer the following
Best way to detect unpatched software in your systems
Vulnerability Scanner
Place where we keep all known risks in our organization
Risk Register
Insider using software that the IT department is unaware of
Shadow IT
Best way to protect all data on a company issued laptop
FDE
Best way to fix known vulnerabilities
Patching
Answer the following.
Company wants to test its employees on clicking on bad links in email.
Simulated Phishing Campaign
Quickest way to get a list of all vulnerabilities on your systems
Automate Scanning
Tool we can use to stop communications with high risk regions
IP Geographical Filtering
Rule that says we must follow all laws based on where we operate
Data Sovereignty
This is a special server dedicated to performing AAA functions.
RADIUS
Answer the following.
Best place to test out malicious software to reverse engineer it.
Sandbox
Granting a user access to a resource is this.
Authentication
Granting a user permissions on a resource is this.
Authorization
Tracking what a user does while accessing a resource is this.
Accounting
This controls email parameters based on whether or not the email passes the security/authentication checks.
DMARC
Answer the following
Automated security controls that help with configuration of cloud security
Guardrails
A Sysadmin is disabling default accounts and removing unnecessary services on a server. What is this called?
Server Hardening
This device protects against insecure communications on a single device.
Host-Based Firewall
This is a way to verify that a device meets security policies and requirements before granting it access to a network.
Compliance Attestation
Specifically protects a web application software by filtering and monitoring web traffic.
WAF
Answer the following
Accommodates a LOW RTO, high cost
Hot Site
Accommodates a HIGH RTO, low cost
Cold Site
A chart that breaks down responsibilities between a CSP and a customer.
Responsibility Matrix
The document that lists the RTO and the RPO
BIA
Creating a false text file designed to attract the attention of an attacker is this.
Honeyfile
This software helps you automate response functions and reduce your workforce requirements.
BYOD
DLP
FIM
SOAR
A preventive control that would stop unauthorized access before it happens.
RADIUS
CSR
UTM
ACL
