WorksheetsMultiple Choice Study Guide - InfoSec
Total questions: 64
Worksheet time: 32mins
What is a Threat?
Hot: fully equipped, Warm: partially ready, Cold: basic infrastructure, Mobile: portable backup site.
A potential cause of an unwanted incident.
Process of evaluating the effects of disruption to business operations.
A plan to restore business operations post-incident or disaster.
What is an Asset?
A sign or warning that an incident may occur, such as scanning or suspicious activity.
Confidentiality, Integrity, and Availability (CIA).
Something of value to the organization.
Includes forensic analysis, AAR (After Action Review), lessons learned.
What is an Attack?
Process of evaluating the effects of disruption to business operations.
An intentional act to cause harm or access unauthorized data.
Rules that protect an organization’s information systems.
Central, Distributed, Coordinating CSIRTs.
What is a Vulnerability?
Select members from IT, security, legal, HR, and other relevant departments.
They help track system activity, detect incidents, and evaluate financial impacts of disruptions.
A weakness that can be exploited by threats.
Confidentiality, Integrity, and Availability (CIA).
What is a Control/Safeguard/Countermeasure?
The organization’s long-term goal.
Ensuring critical business functions continue during and after a disaster.
RAID combines multiple drives for redundancy/performance; RAID 0 provides striping without redundancy.
A measure taken to reduce risk.
What is Trespass?
Unauthorized access to systems or data.
Detects deviations from normal behavior to identify possible threats.
Reducing the impact or likelihood of a risk.
A weakness that can be exploited by threats.
What are Malicious Code Threats?
An intentional act to cause harm or access unauthorized data.
Threats like viruses, worms, and trojan horses.
Planning how to detect and respond to incidents.
Ensuring critical business functions continue during and after a disaster.
What are Worms?
Hot: fully Hot: fully equipped, Warm: partially ready, Cold: basic infrastructure, Mobile: portable backup site
Self-replicating programs that spread without user interaction
Shared backup site; disadvantage: availability not guaranteed in a widespread disaster
Strategies to recover IT systems after a disaster
What are Viruses?
Malicious code that attaches to programs and needs user action to spread.
The process of defining strategy and direction.
Shifting the risk to a third party (e.g., insurance).
The maximum tolerable period in which data might be lost due to a disruption.
What is Transference in risk control?
Reactive, Proactive, and Security Quality Management Services.
Reducing the impact or likelihood of a risk.
Shifting the risk to a third party (e.g., insurance).
Vulnerability assessment, technology watch, and patch management.
What is Mitigation?
To manage the response process and restore normal operations after an incident.
Methods include classroom (high cost), online (medium), self-paced (low).
A team that quickly responds to and manages security incidents.
Reducing the impact or likelihood of a risk.
What is Acceptance?
Mutual: shared responsibilities; Service: SLAs for services; NDA: confidentiality of shared information
Recognizing and accepting the risk without action
A dedicated high-speed network for block-level storage access
Includes forensic analysis, AAR (After Action Review), lessons learned.
What is a Contingency Plan?
Malicious code that attaches to programs and needs user action to spread.
A potential cause of an unwanted incident.
A strategy for responding to potential future events.
A measure taken to reduce risk.
What is Business Impact Analysis (BIA)?
Shared backup site; disadvantage: availability not guaranteed in a widespread disaster.
Full, incremental, and differential backups.
RAID combines multiple drives for redundancy/performance; RAID 0 provides striping without redundancy.
Process of evaluating the effects of disruption to business operations.
What is Incident Response Planning (IRP)?
A dedicated high-speed network for block-level storage access.
A plan to restore business operations post-incident or disaster.
Planning how to detect and respond to incidents.
A measure taken to reduce risk.
What is Disaster Recovery Planning (DRP)?
Plan development, preparation, detection/analysis, containment, eradication, recovery, post-incident.
Strategies to recover IT systems after a disaster.
Malicious code that attaches to programs and needs user action to spread.
The maximum tolerable time to restore a system or process after a disruption.
What is Business Continuity Planning (BCP)?
Ensuring critical business functions continue during and after a disaster.
A plan to restore business operations post-incident or disaster.
Backups are for short-term recovery; archives are for long-term data retention and compliance.
Process of evaluating the effects of disruption to business operations.
What is a policy?
Initiate project, identify stakeholders, define services, structure team, deploy resources, launch.
Data collection, analysis of business impacts, and reporting with recommendations.
A software-based emulation of a physical computer running an OS and applications.
A formal statement of rules and guidelines.
What is a standard?
A. A detailed requirement derived from a policy.
B. Reactive, Proactive, and Security Quality Management Services.
C. An intentional act to cause harm or access unauthorized data.
D. Strategies to recover IT systems after a disaster.
What is a mission?
The organization's core purpose.
Planning how to detect and respond to incidents.
A potential cause of an unwanted incident.
A dedicated high-speed network for block-level storage access.
What is a vision?
Plan development, preparation, detection/analysis, containment, eradication, recovery, post-incident.
The organization's long-term goal.
Strategies to recover IT systems after a disaster.
Incident: security breach; Response: actions taken; Activation: triggering the plan; Policy: formal guidelines.
What is strategic planning?
Systems like honeypots, honeynets, and trap-and-trace tools used to detect and respond to attacks automatically.
The process of defining strategy and direction.
The organization's core purpose.
The maximum tolerable period in which data might be lost due to a disruption.
What is an information security policy?
Rules that protect an organization's information systems.
Data collection, analysis of business impacts, and reporting with recommendations.
Mutual: shared responsibilities; Service: SLAs for services; NDA: confidentiality of shared information.
The organization's core purpose
What are the Contingency Planning Management Team's (CPMT) responsibilities?
Full, incremental, and differential backups.
Detecting attacks based on known patterns (signatures), e.g., DNS cache poisoning.
To develop the contingency planning policy, conduct the BIA, and coordinate all CP efforts.
Data collection, analysis of business impacts, and reporting with recommendations.
What are the CPMT positions and which one is a high-level manager?
Strategies to recover IT systems after a disaster.
Plan development, preparation, detection/analysis, containment, eradication, recovery, post-incident.
Positions include the CP coordinator, business unit representatives, IT representatives, and a high-level manager who provides oversight.
By correlating alerts, logs, and verifying abnormal behavior patterns.
What are the core information security principles?
An intentional act to cause harm or access unauthorized data.
Initiate project, identify stakeholders, define services, structure team, deploy resources, launch.
Confidentiality, Integrity, and Availability (CIA).
Incident: security breach; Response: actions taken; Activation: triggering the plan; Policy: formal guidelines.
What are IT application/system logs and financial reports used for?
They help track system activity, detect incidents, and evaluate financial impacts of disruptions.
Plan development, preparation, detection/analysis, containment, eradication, recovery, post-incident.
An intentional act to cause harm or access unauthorized data.
A comprehensive process for preparing for unexpected events or disruptions.
What is Recovery Point Objective (RPO)?
The maximum tolerable period in which data might be lost due to a disruption.
A team that quickly responds to and manages security incidents.
An intentional act to cause harm or access unauthorized data.
Hot: immediate recovery, Warm: limited downtime, Cold: longer setup time.
What is Recovery Time Objective (RTO)?
The maximum tolerable time to restore a system or process after a disruption.
Strategies to recover IT systems after a disaster.
Mutual: shared responsibilities; Service: SLAs for services; NDA: confidentiality of shared information.
A team that quickly responds to and manages security incidents.
What are the three key stages in conducting Business Impact Analysis (BIA)?
Vulnerability assessment, technology watch, and patch management
Data collection, analysis of business impacts, and reporting with recommendations
The organization's core purpose
Self-replicating programs that spread without user interaction
What is contingency planning (CP)?
Threats like viruses, worms, and trojan horses.
Recognizing and accepting the risk without action.
RAID combines multiple drives for redundancy/performance; RAID 0 provides striping without redundancy.
A comprehensive process for preparing for unexpected events or disruptions.
What is incident response (IR) process?
A structured approach to handle security incidents efficiently and effectively.
The process of defining strategy and direction.
A team that quickly responds to and manages security incidents.
Something of value to the organization.
What is a business resumption plan?
A plan to restore business operations post-incident or disaster.
The organization's core purpose.
Select members from IT, security, legal, HR, and other relevant departments.
A comprehensive process for preparing for unexpected events or disruptions.
When do we use data backup and archive?
Shifting the risk to a third party (e.g., insurance)
Fully: external provider manages all; Partially: internal team shares responsibilities with provider
Includes forensic analysis, AAR (After Action Review), lessons learned
Backups are for short-term recovery; archives are for long-term data retention and compliance
When are hot, warm, and cold servers used?
Rules that protect an organization’s information systems.
Hot: immediate recovery, Warm: limited downtime, Cold: longer setup time.
A senior leader who advocates and supports the CSIRT formation.
Fully: external provider manages all; Partially: internal team shares responsibilities with provider.
What are the types of backup?
By correlating alerts, logs, and verifying abnormal behavior patterns.
Full, incremental, and differential backups.
Detecting attacks based on known patterns (signatures), e.g., DNS cache poisoning.
Positions include the CP coordinator, business unit representatives, IT representatives, and a high-level manager who provides oversight.
What is RAID and RAID 0?
By correlating alerts, logs, and verifying abnormal behavior patterns.
A plan to restore business operations post-incident or disaster.
Detects deviations from normal behavior to identify possible threats
RAID combines multiple drives for redundancy/performance; RAID 0 provides striping without redundancy
What is Network-Attached Storage (NAS)?
Shifting the risk to a third party (e.g., insurance).
A storage device connected to a network that allows data access to multiple users.
Includes forensic analysis, AAR (After Action Review), lessons learned.
Determining the group or organization that the CSIRT serves and supports.
What is a Storage Area Network (SAN)?
Reactive, Proactive, and Security Quality Management Services.
A software-based emulation of a physical computer running an OS and applications.
Positions include the CP coordinator, business unit representatives, IT representatives, and a high-level manager who provides oversight.
A dedicated high-speed network for block-level storage access.
What is a virtual machine?
A software-based emulation of a physical computer running an OS and applications.
Data collection, analysis of business impacts, and reporting with recommendations.
A formal statement of rules and guidelines.
Fully: external provider manages all; Partially: internal team shares responsibilities with provider
What are hot, warm, cold, and mobile sites?
Hot: fully equipped, Warm: partially ready, Cold: basic infrastructure, Mobile: portable backup site
The organization's core purpose
Data collection, analysis of business impacts, and reporting with recommendations
Ensuring critical business functions continue during and after a disaster
What is time-share and its disadvantages?
Planning how to detect and respond to incidents.
By correlating alerts, logs, and verifying abnormal behavior patterns.
Includes forensic analysis, AAR (After Action Review), lessons learned.
Shared backup site; disadvantage: availability not guaranteed in a widespread disaster.
What are mutual, service, and nondisclosure agreements?
Mutual: shared responsibilities; Service: SLAs for services; NDA: confidentiality of shared information.
Shared backup site; disadvantage: availability not guaranteed in a widespread disaster.
Central, Distributed, Coordinating CSIRTs.
The organization's long-term goal.
What are the Incident Planning Stages?
Central, Distributed, Coordinating CSIRTs.
Plan development, preparation, detection/analysis, containment, eradication, recovery, post-incident.
Unauthorized access to systems or data.
A detailed requirement derived from a policy.
How to form the Incident Response Planning (IRP) team?
Confidentiality, Integrity, and Availability (CIA).
A plan to restore business operations post-incident or disaster.
A team that quickly responds to and manages security incidents.
Select members from IT, security, legal, HR, and other relevant departments.
Define Incident, Incident Response, Activation, and Policy.
Methods include classroom (high cost), online (medium), self-paced (low).
To manage the response process and restore normal operations after an incident.
Mutual: shared responsibilities; Service: SLAs for services; NDA: confidentiality of shared information.
Incident: security breach; Response: actions taken; Activation: triggering the plan; Policy: formal guidelines.
What is CSIRT reaction force?
Data collection, analysis of business impacts, and reporting with recommendations.
Determining the group or organization that the CSIRT serves and supports.
A team that quickly responds to and manages security incidents.
Unauthorized access to systems or data.
What is planning for after the incident?
Positions include the CP coordinator, business unit representatives, IT representatives, and a high-level manager who provides oversight
A sign or warning that an incident may occur, such as scanning or suspicious activity
Includes forensic analysis, AAR (After Action Review), lessons learned
Select members from IT, security, legal, HR, and other relevant departments
What are training delivery methods and cost levels?
To manage the response process and restore normal operations after an incident.
Malicious code that attaches to programs and needs user action to spread.
Methods include classroom (high cost), online (medium), self-paced (low).
The maximum tolerable period in which data might be lost due to a disruption.
What is a precursor in detecting incidents?
Recognizing and accepting the risk without action.
Select members from IT, security, legal, HR, and other relevant departments.
The organization's long-term goal.
A sign or warning that an incident may occur, such as scanning or suspicious activity.
What are definite indicators?
Threats like viruses, worms, and trojan horses.
Clear evidence that an incident is occurring, like alerts from IDPS.
Select members from IT, security, legal, HR, and other relevant departments.
A comprehensive process for preparing for unexpected events or disruptions.
How to identify real incidents?
By correlating alerts, logs, and verifying abnormal behavior patterns.
The organization's core purpose.
Reducing the impact or likelihood of a risk.
A dedicated high-speed network for block-level storage access.
What is signature matching in IDPS?
Backups are for short-term recovery; archives are for long-term data retention and compliance.
Detecting attacks based on known patterns (signatures), e.g., DNS cache poisoning.
To manage the response process and restore normal operations after an incident.
A measure taken to reduce risk.
What is automated response?
Process of evaluating the effects of disruption to business operations.
Systems like honeypots, honeynets, and trap-and-trace tools used to detect and respond to attacks automatically.
The process of defining strategy and direction.
Data collection, analysis of business impacts, and reporting with recommendations.
What is anomaly-based IDPS?
A comprehensive process for preparing for unexpected events or disruptions.
Includes forensic analysis, AAR (After Action Review), lessons learned.
Detects deviations from normal behavior to identify possible threats.
Reactive, Proactive, and Security Quality Management Services
What is the IRP team’s primary responsibility?
The organization's core purpose.
They help track system activity, detect incidents, and evaluate financial impacts of disruptions.
The maximum tolerable period in which data might be lost due to a disruption.
To manage the response process and restore normal operations after an incident.
What are the steps to build a formal CSIRT?
Initiate project, identify stakeholders, define services, structure team, deploy resources, launch.
A measure taken to reduce risk.
A strategy for responding to potential future events.
Data collection, analysis of business impacts, and reporting with recommendations.
Who is the CSIRT champion?
Central, Distributed, Coordinating CSIRTs.
A measure taken to reduce risk.
Self-replicating programs that spread without user interaction.
A senior leader who advocates and supports the CSIRT formation.
What are CSIRT structural categories?
The organization's core purpose
Positions include the CP coordinator, business unit representatives, IT representatives, and a high-level manager who provides oversight
A measure taken to reduce risk
Central, Distributed, Coordinating CSIRTs
What is the difference between fully and partially outsourced models?
Shifting the risk to a third party (e.g., insurance).
Fully: external provider manages all; Partially: internal team shares responsibilities with provider.
To develop the contingency planning policy, conduct the BIA, and coordinate all CP efforts.
The maximum tolerable period in which data might be lost due to a disruption.
What are the three CSIRT service categories?
Shared backup site; disadvantage: availability not guaranteed in a widespread disaster.
Reactive, Proactive, and Security Quality Management Services.
A plan to restore business operations post-incident or disaster.
Recognizing and accepting the risk without action.
What is identifying your constituency?
Malicious code that attaches to programs and needs user action to spread.
Reactive, Proactive, and Security Quality Management Services.
Fully: external provider manages all; Partially: internal team shares responsibilities with provider.
Determining the group or organization that the CSIRT serves and supports.
What is identifying your constituency?
Malicious code that attaches to programs and needs user action to spread
Reactive, Proactive, and Security Quality Management Services
Fully: external provider manages all; Partially: internal team shares responsibilities with provider
Determining the group or organization that the CSIRT serves and supports
What are examples of CSIRT services?
Vulnerability assessment, technology watch, and patch management
A software-based emulation of a physical computer running an OS and applications
A plan to restore business operations post-incident or disaster
The organization’s long-term goal
