NEW
Font size
WorksheetsCybersecurity Controls and Threat Intelligence Quiz
Total questions: 30
Worksheet time: 15mins
Which of the following is an example of a technical control?
Annual security awareness training
Role-based access control (RBAC)
Disaster recovery policy
Hiring background checks
A company implements automatic patch updates for its systems every week. What type of control is this?
Detective
Operational
Technical
Compensating
After a phishing attack compromises user accounts, the security team restores affected systems from clean backups. What type of control is this?
Preventive
Detective
Corrective
Managerial
Due to high cost, a company decides not to use a fingerprint scanner and instead implements multi-factor authentication. What kind of control is MFA in this context?
Technical
Compensating
Preventive
Managerial
Which control type involves creating policies and oversight for how security measures are developed and managed?
Operational
Technical
Managerial
Corrective
A cybersecurity analyst detects unusual outbound traffic from a workstation and uses log analysis to investigate. What control type is being used?
Preventive
Detective
Responsive
Operational
Which of the following best describes the purpose of passive discovery?
Simulate attacks to test systems
Actively probe devices for weaknesses
Gather network information without direct interaction
Document known vulnerabilities
An organization maps out all possible ways a threat actor might infiltrate its systems. What is this process called?
Asset inventory
Threat modeling
Log analysis
Risk mitigation
Which control type is designed to stop a threat before it causes harm?
Detective
Responsive
Preventive
Corrective
A server is scanned by an unknown external IP. The security team follows a documented checklist to analyze the event. What type of control is being applied?
Responsive
Preventive
Detective
Managerial
Your company cannot patch a known vulnerability due to compatibility issues. A temporary access control is put in place instead. What type of control is this?
Preventive
Compensating
Detective
Corrective
Before applying a security patch to a production environment, a team ensures the update won't impact operations. What step of the patch management process is this?
Rollback
Testing
Validation
Implementation
A critical patch is applied during scheduled downtime. Post-deployment, systems begin to crash. What should the administrator do next?
Reapply the patch
Execute rollback procedures
Wait for vendor updates
Isolate affected users
Which control type is most concerned with creating policies and aligning security objectives with business goals?
Technical
Operational
Corrective
Managerial
What risk management strategy is being applied when an organization purchases cyber insurance to cover potential breaches?
Accept
Transfer
Avoid
Mitigate
A development team is coding a web application and wants to prevent XSS and SQL injection attacks. Which practice should they prioritize?
Data encryption
Secure file permissions
Input validation and output encoding
Role-based access controls
What is the main purpose of governance in patch and configuration management?
Monitor patch deployment tools
Enforce antivirus updates
Define frameworks and security policies
Select hardware and vendor solutions
What does a bug bounty program encourage?
Internal audits by security staff
Attack simulations using red teams
Ethical hackers to report vulnerabilities
Patch updates from vendors
A third-party library used by your application has a critical vulnerability, but no patch has been released. Your team applies firewall rules and limits access to reduce risk. What strategy is this?
Accept
Transfer
Mitigate
Avoid
Which of the following steps comes before deploying a patch to production environments?
Monitoring system logs
Testing the patch in a sandbox
Disabling backups
Encrypting affected data
Employees in your organization unknowingly install malware from a trusted vendor's update server that was compromised. What type of attack is this?
Social engineering
Supply chain attack
Insider threat
Zero-day exploit
A threat actor uses custom tools to remain undetected for months while targeting a government database. What type of actor is most likely responsible?
Script kiddie
Hacktivist
Nation-state
Insider
An analyst maps out a cyber intrusion by focusing on the adversary, infrastructure, capability, and victim. Which analytical model is being used?
MITRE ATT&CK
Diamond Model
Cyber Kill Chain
STRIDE
Which framework is specifically used to track attacker behaviors by documenting tactics, techniques, and procedures (TTPs)?
OWASP
MITRE ATT&CK
Cyber Kill Chain
NIST RMF
A junior analyst detects brute-force login attempts and references the MITRE ATT&CK database to determine tactics used. What is she doing?
Mapping adversarial behavior
Verifying application versioning
Writing a risk report
Performing vulnerability scanning
Which of the following best describes 'TTPs' used in cyber threat intelligence?
Time-sensitive parameters
Transport tunneling protocols
Tactics, Techniques, and Procedures
Tool Testing Parameters
Which framework breaks a cyberattack into steps like reconnaissance, delivery, exploitation, and actions on objectives?
OWASP Testing Guide
Cyber Kill Chain
MITRE ATT&CK
Diamond Model
A user bypasses monitoring controls to send sensitive data outside the organization using a software flaw. What type of insider threat is this?
Passive
Unintentional
Intentional
Negligent
Which intelligence source usually requires a paid subscription or vendor relationship to access?
Open source
Internal logs
Social media
Closed source
Which of the following traits determine the quality of threat intelligence?
Speed, simplicity, and control
Encryption, integrity, and trust
Timeliness, relevancy, and accuracy
Detection, deletion, and durability
