wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

IT23L Review 6,7,-8

Total questions: 102

Worksheet time: 53mins

Name
Class
Date
1.

Which activity by anniversary is an example of an exploit that is attempting to gain

user credentials?

a)

Installing a backdoor in order to enable two way communication with the device

b)

Obtaining a directory listing of files located on the web date database server

c)

Sending an email with a link to a fictitious web portal login page

d)

Executing a remote port scan of all the enterprise registered IP addresses

2.

You are monitoring the syslog server and observe that the dns server is sending

messages with a warning severity. what do these messages indicate about the

operation of the dns server?

a)

The server has a hardware error that does not require immediate attention

b)

An error condition is occurring that must be

addressed immediately

c)

Condition exists that will cause errors in the future if the issue is not fixed

d)

The DNS server is unusable due to a severe malfunction and is shutting down.

3.

What is the purpose of a hypervisor?

a)

It monitors and logs network traffic for malicious pockets

b)

It creates and runs virtual machines

c)

It provides and monitors firewall services for

cloud computing

d)

It provides and services a gateway between users and the internet

4.

What you should create to prevent spoofing of the internal network?

a)

A DNS Record

b)

an ACL (access control list)

c)

A Net Rule

d)

A Record In the Host File

5.

What mitigate the impact of the incident?

a)

Containment, Eradication, And Recovery

b)

Post-incident activity and preparation

c)

Detection and Analysis

d)

Preparation

6.

What reports, the cause and cost of the incident and the steps to prevent future incidents.

a)

Containment, Eradication, And Recovery

b)

Post-incident activity and preparation

c)

Detection and Analysis

d)

Preparation

7.

What evaluate incident indicators to determine whether they are legitimate attacks and alerts the organization of the incident?

a)

Containment, Eradication, And Recovery

b)

Post-incident activity and preparation

c)

Detection and Analysis

d)

Preparation

8.

What establishes an incident response capability to ensure that organizational assets are sufficiently secure?

a)

Containment, Eradication, And Recovery

b)

Post-incident activity and preparation

c)

Detection and Analysis

d)

Preparation

9.

We need to filter the websites that are available to employees on the company

network. which type of device should you deploy?

a)

IDS

b)

IPS

c)

PROXY SERVER

d)

HONEY POT

10.

Match the correct answer.

People, Property, Or Data

a)

Asset

b)

Risk

c)

Threat

d)

Vulnerability

11.

Match the correct answer.

An Action that Causes Negative Impact

a)

Asset

b)

Risk

c)

Threat

d)

Vulnerability

12.

Match the correct answer.

The Potential For Loss, Damage Or Destruction

a)

Asset

b)

Risk

c)

Threat

d)

Vulnerability

13.

Match the correct answer.

The weakness that potentially exposes

Organizations for cyber attacks are:

a)

Asset

b)

Risk

c)

Threat

d)

Vulnerability

14.

Which wireless encryption technology requires AES to secure home wireless

networks?

a)

WPA3

b)

TKIP

c)

WEP

d)

WPA2

15.

A corporation hires a group of experienced cyber criminals to create a prolonged and in-depth presthis presence will allow corporations to steal or sabotage sensitive data from their competitors. whdescribe?

a)

Man in the Middle

b)

APT (Advanced Persistent Threat)

c)

DDOS

d)

Ransomware

16.

A security analyst may use a disgruntled employee's network credentials to monitor

behavior.

a)

True

b)

False

17.

So what contains events that are received from programs running on the

device?

a)

Application Logs

b)

Setup Logs

c)

System Logs

d)

Security Logs

18.

Record information about software installation and operating system updates.

a)

Application Logs

b)

Setup Logs

c)

System Logs

d)

Security Logs

19.

List events generated by the operation of hardware, drivers and processes.

a)

Application Logs

b)

Setup Logs

c)

System Logs

d)

Security Logs

20.

Record the success or failure of the audit

policy events

a)

Application Logs

b)

Setup Logs

c)

System Logs

d)

Security Logs

21.

After an administrator installs an operating system update on a laptop, the laptop

user can no longer print to their wireless printer. what should solve the issue?

a)

Install a new device driver for the wireless printer

b)

Update the firmware on the laptop

c)

Reinstall the same service

pack

d)

Check for patches for wireless printers

22.

Your organization as IEM system alerts you that users are connecting to an unusual

url. you need to determine whether the URL is malicious and what type of threat it

represents. what should you do?

a)

Visit the URL to determine whether the website is legitimate

b)

Ask users why they visited the website

c)

Submit the URL to the threat intelligence portal for analysis

d)

block the URL by placing it on the network block

list.

23.

Which activity is an example of active

recognition performed during a penetration test?

a)

Search the who's database for the owner and technical contact information for a

domain

b)

Gathering employees

information from available web directories and social media

c)

Perform an NMAP port scan on the LAN to determine the types of

connected devices and open ports

d)

Using a browser to view the

http source code of company web pages

24.

What are two natural disasters that would use a company to implement a disaster

recovery plan? choose two.

a)

Nuclear Contamination

b)

Hazardous Material Spills

c)

Floods

d)

Volcanic Eruptions

25.

Customers of an online shopping store are complaining that they cannot visit the

website. as an it technician, you restart the website. after 30 minutes, the website

crashes again. you suspect that the website has experienced a cyber attack. so which

type of cyber security threat should you investigate?

a)

Ransomware

b)

Denial of Service (Dos)

c)

Spear Phishing

d)

Social Engineering

26.

What enables the network security team to keep track of the operating system

versions, security updates and patches on end user devices?

a)

Incident Management

b)

Business Continuity Planning

c)

Asset Management

d)

Security Policies and

Procedures

27.

Which two basic metrics should be taken into consideration when assigning a

severity to a vulnerability during an assessment? choose two

a)

The impacts that exploitation of the vulnerability will have on the

organization

b)

The time involved in choosing replacement software to replace older system

c)

The age of the hardware running the software that contains vulnerability

d)

The likelihood that an adversary can and will exploit the vulnerability

28.

in order to do online banking, enter a strong password and then enter the 5 digit

code sent to you on your smartphone. What type of authentication does this

situation

description.

a)

Radius

b)

VPN

c)

Multifactor Authentication

d)

Triple

29.

A cybersecurity analyst is investigating an unknown executable file discovered a

linux desktop computer. the analyst enters the

following command in the terminal . What is the purpose of this command

a)

To display the content of a

text file.

b)

Navigate to the folder that is passed as an argument to the command.

c)

, To display the file permissions and ownership of the executable file.

d)

To open a text editor

30.

Security analysts may have access to employee data on the company server, if

authorized.

a)

True

b)

False

31.

You work for a community healthcare organization that uses an electronic health

record system. you have implemented the physical and technical safeguards

required by HIPAA. you need to prove that the system is compliant with those

safeguards. which two approaches should you use to verify that the system is

compliant? choose two.

a)

It Auditing

b)

Penetration Testing

c)

Automatic Log off Implementation

d)

Security Awareness Training

32.

What does hashing provide for data communication

a)

Data Encryption

b)

Data Non Repudiation

c)

Origin Authentication.

d)

Data Integrity

33.

Match the Correct answer.

NESSUS SCANNER

CVSS (COMMON VULNERABILITY SCORING SYSTEM)

a)

Discovering

b)

Prioritizing

c)

Remediating

34.

Match the Correct answer.

NMAP

a)

Discovering

b)

Prioritizing

c)

Remediating

35.

Match the Correct answer.

PATCH MANAGEMENT SOFTWARE WINDOWS AUTO UPDATE AND PATCH

a)

Discovering

b)

Prioritizing

c)

Remediating

36.

A security analyst may share sensitive

data with unauthorized users

a)

True

b)

False

37.

You are reviewing the company's remote access procedures and noticed that telnet

is being used to connect to a corporate database server. to check on inventory levels,

which two actions should you take immediately? choose two

a)

Reconfigure the server to only accept http connections

b)

Force users to implement secure telnet passwords.

c)

Disable telnet access on the server

d)

Implement SSH access on the server

38.

A system on your network is experiencing slower than usual response times. in

order to gather information about the status of the system, you issue a netstat minus

1 command to display all the TCP ports that are in the listening state. what does the

listening state indicate about these ports?

a)

The ports are actively connected to another system or process

b)

Remote and disconnected and the ports are closing

c)

The ports are open on the system and are waiting for connections

d)

The state of the connection on the ports is

unknown

39.

You are a security technician. you just completed a full scan of a windows 10 pc.

where should you go to view the scan results?

a)

Windows System logs

b)

Windows Application Logs

c)

Windows Security

d)

Windows Task Manager

40.

Several staff members are experiencing unexplained computer crashes and many

unwanted popup messages. which 2 actions should you take immediately to address

the problem without impacting data? choose two.

a)

Deploy a policy to install and automatically upgrade antivirus and antimalware software

b)

Reinstall windows on the affected workstations

c)

Scan affected workstations and remove malware

d)

Configure the network firewall to block

malware from entering the internal network.

41.

A security analyst discovers that a hacker was able to gain root access to an

enterprise linux server. the hacker accessed the server as a guest and used a

program to bypass the root

password, and then killed essential server processes as the root user. which type of

endpoint attack is this?

a)

Buffer Overflow

b)

Boot Force

c)

DDOS

d)

Privilege escalation.

42.

What are the two disadvantages of public vulnerability databases? choose 2.

a)

It is costly for intelligence analysts to document and submit

newly discovered vulnerabilities

b)

It can take a long time for reported vulnerabilities to be investigated and

approved for addition to the databases

c)

Publicly available databases are incompatible with most security platforms

d)

Threat actors can access the databases to learn how to vary the threats to

avoid detection

43.

Match the correct answer

Discover unwanted events

a)

Detective Measures

b)

Preventive Measures

c)

Corrective Measures

44.

Match the correct answer

Avert the occurrence of an event.

a)

Detective Measures

b)

Preventive Measures

c)

Corrective Measures

45.

Match the correct answer

Restore a system after the event

a)

Detective Measures

b)

Preventive Measures

c)

Corrective Measures

46.

Several employees complained that the company's intranet site is no longer

accepting their login information. you attempt to connect using

the url and noticed some misspellings on the site. when you connect using the IP

address, the site functions normally. what should you do?

a)

Update the web server software to the latest version

b)

Restore about a backup copy of the authentication database

c)

Verify the accuracy of the entry for the site in the local DNS server

d)

Take the company web portal offline immediately.

47.

You are security analyst. you are reviewing the output from siem. You will notice an

alert concerning malicious files detected by IDs. after reviewing the user's device

and posture information, you have determined that it is a valid incident. what

should you do next?

a)

Log the alert and watch for a second occurrence.

b)

Escalate The Situation Immediately.

c)

update the documentation to include the new alert information.

d)

Prepare Notes To Present At The Weekly Cyber Security Team Meeting.

48.

Yes or No if its typical located in company's demilitarized zone:

Directory

a)

Yes

b)

No

49.

Yes or No if its typical located in company's demilitarized zone:

Email

a)

Yes

b)

No

50.

Yes or No if its typical located in company's demilitarized zone:

Web

a)

Yes

b)

No

51.

Yes or No if its typical located in company's demilitarized zone:

Print

a)

Yes

b)

No

52.

Yes or No if its typical located in company's demilitarized zone:

Zenmap is a GUI app that runs nmap.

a)

Yes

b)

No

53.

Yes or No if its typical located in company's demilitarized zone:

ss is the Linux equivalent of netstat.

a)

Yes

b)

No

54.

Yes or No if its typical located in company's demilitarized zone:

netstat runs in a GUI environment.

a)

Yes

b)

No

55.

Yes or No if its typical located in company's demilitarized zone:

netstat shows active and waiting ports for connections.

a)

Yes

b)

No

56.

In a DHCP ___________attack, threat actors configure a fake DHCP server on the

network to issue DHCP addresses to clients.

a)

Rogue DHCP Attack

b)

DHCP Starvation Attack

c)

DNS Amplification Attack

d)

DNS Spoofing Attack

57.

In a DHCP __________attack, threat actors flood the DHCP server with DHCP requests to use up all the available IP addresses that the legitimate DHCP server can issue.

a)

Rogue DHCP Attack

b)

DHCP Starvation Attack

c)

DNS Amplification Attack

d)

DNS Spoofing Attack

58.

In a DNS __________attack, threat actors use publicly accessible open DNS servers to flood a target with DNS response traffic

a)

Rogue DHCP Attack

b)

DHCP Starvation Attack

c)

DNS Amplification Attack

d)

DNS Spoofing Attack

59.

In a DNS ___________attack, threat actors change the A record for your domain’s IP address to point to a predetermined address of their choice.

a)

Rogue DHCP Attack

b)

DHCP Starvation Attack

c)

DNS Amplification Attack

d)

DNS Spoofing Attack

60.

Match the answer.

The condition should be corrected immediately.

a)

Leve 1 (Alert)

b)

Level 4 (Warning)

c)

Level 5 (Notice)

d)

Level 6 (Informational)

61.

Match the answer.

An error may occur if the situation is not remedied.

a)

Leve 1 (Alert)

b)

Level 4 (Warning)

c)

Level 5 (Notice)

d)

Level 6 (Informational)

62.

Match the answer.

Unusual event but not an error.

a)

Leve 1 (Alert)

b)

Level 4 (Warning)

c)

Level 5 (Notice)

d)

Level 6 (Informational)

63.

Match the answer.

Normal operation. The situation requires no intervention.

a)

Leve 1 (Alert)

b)

Level 4 (Warning)

c)

Level 5 (Notice)

d)

Level 6 (Informational)

64.

Threat actors send emails randomly to a very large number of recipients with

the intent to gather information for fraud or identity theft.

a)

Phishing

b)

Smishing

c)

Vishing

65.

Threat actors send emails that are carefully designed to get a single recipient within an organization to respond and unknowingly install malware onto their system

a)

Phishing

b)

Smishing

c)

Vishing

66.

Threat actors create fraudulent text messages to try to lure victims into revealing account information or installing malware

a)

Phishing

b)

Smishing

c)

Vishing

67.

Threat actors use voice calls to manipulate an individual into releasing confidential data.

a)

Phishing

b)

Smishing

c)

Vishing

68.

Hardened facilities and alternate sites.

a)

Natural Disasters

b)

Cyberattack

c)

Supply-Chain Disruptions

d)

Employee Errors

69.

Firewalls, IDS and IPS, and Log Analyzers.

a)

Natural Disasters

b)

Cyberattack

c)

Supply-Chain Disruptions

d)

Employee Errors

70.

Alternate sources, and inventory management

a)

Natural Disasters

b)

Cyberattack

c)

Supply-Chain Disruptions

d)

Employee Errors

71.

Standard procedures, and training

a)

Natural Disasters

b)

Cyberattack

c)

Supply-Chain Disruptions

d)

Employee Errors

72.

You need to implement a multifactor authentication system for physical

access to a building. You are currently using only a fingerprint scan.

a)

Retinal Scan

b)

Facial Recognition

c)

Voiceprint Analysis

d)

ID Card

73.

Recover is one of the core functions of the NIST Cybersecurity

a)

True

b)

False

74.

Protects the personal information of members of the European Union

a)

GDPR (General Data Protection Regulation)

b)

HIPAA (Health Insurance Portability and Accountability Act)

c)

PCI-DSS (Payment Card Industry Data Security Standard)

d)

FERPA (Family Educational Rights and Privacy Act)

e)

FISMA (Federal Information Security Management Act)

75.

Protects the healthcare information of individuals

a)

GDPR (General Data Protection Regulation)

b)

HIPAA (Health Insurance Portability and Accountability Act)

c)

PCI-DSS (Payment Card Industry Data Security Standard)

d)

FERPA (Family Educational Rights and Privacy Act)

e)

FISMA (Federal Information Security Management Act)

76.

Protects the credit card information of individuals

a)

GDPR (General Data Protection Regulation)

b)

HIPAA (Health Insurance Portability and Accountability Act)

c)

PCI-DSS (Payment Card Industry Data Security Standard)

d)

FERPA (Family Educational Rights and Privacy Act)

e)

FISMA (Federal Information Security Management Act)

77.

Protects the educational records of individuals

a)

GDPR (General Data Protection Regulation)

b)

HIPAA (Health Insurance Portability and Accountability Act)

c)

PCI-DSS (Payment Card Industry Data Security Standard)

d)

FERPA (Family Educational Rights and Privacy Act)

e)

FISMA (Federal Information Security Management Act)

78.

Protects information about individuals that is stored by federal agencies

a)

GDPR (General Data Protection Regulation)

b)

HIPAA (Health Insurance Portability and Accountability Act)

c)

PCI-DSS (Payment Card Industry Data Security Standard)

d)

FERPA (Family Educational Rights and Privacy Act)

e)

FISMA (Federal Information Security Management Act)

79.

Detects network connections routing tables interface statistics

masquerade connections and multicast membership

a)

netstat

b)

NMap

c)

nslookup

80.

Scans networks for open ports service versions and operating system information

a)

netstat

b)

NMap

c)

nslookup

81.

Performs DNS queries to obtain domain name of IP address mapping information

a)

netstat

b)

NMap

c)

nslookup

82.

Respond is more of the functions of the NIST Security Framework

a)

True

b)

False

83.

A company backs up user data to the cloud by using this backup strategy

- A full back up every Sunday at 6:00PM

- An incremental back up every day except Sunday at 6:00PM

A user accidentally deleted their documents at 8:00AM Friday it is now

Saturday at 10:00PM

You need to recover the user’s documents to their most recent versions by

using the fewest number of backups.

Which backups should you restore?

Move/Match the required backups to the answer area place them in the

correct order.


"Day 1"

a)

Monday

b)

Tuesday

c)

Wednesday

d)

Thursday

e)

Friday

84.

A company backs up user data to the cloud by using this backup strategy

- A full back up every Sunday at 6:00PM

- An incremental back up every day except Sunday at 6:00PM

A user accidentally deleted their documents at 8:00AM Friday it is now

Saturday at 10:00PM

You need to recover the user’s documents to their most recent versions by

using the fewest number of backups.

Which backups should you restore?

Move/Match the required backups to the answer area place them in the

correct order.


"Day 2"

a)

Monday

b)

Tuesday

c)

Wednesday

d)

Thursday

e)

Friday

85.

A company backs up user data to the cloud by using this backup strategy

- A full back up every Sunday at 6:00PM

- An incremental back up every day except Sunday at 6:00PM

A user accidentally deleted their documents at 8:00AM Friday it is now

Saturday at 10:00PM

You need to recover the user’s documents to their most recent versions by

using the fewest number of backups.

Which backups should you restore?

Move/Match the required backups to the answer area place them in the

correct order.


"Day 3"

a)

Monday

b)

Tuesday

c)

Wednesday

d)

Thursday

e)

Friday

86.

A company backs up user data to the cloud by using this backup strategy

- A full back up every Sunday at 6:00PM

- An incremental back up every day except Sunday at 6:00PM

A user accidentally deleted their documents at 8:00AM Friday it is now

Saturday at 10:00PM

You need to recover the user’s documents to their most recent versions by

using the fewest number of backups.

Which backups should you restore?

Move/Match the required backups to the answer area place them in the

correct order.


"Day 4"

a)

Monday

b)

Tuesday

c)

Wednesday

d)

Thursday

e)

Friday

87.

A company backs up user data to the cloud by using this backup strategy

- A full back up every Sunday at 6:00PM

- An incremental back up every day except Sunday at 6:00PM

A user accidentally deleted their documents at 8:00AM Friday it is now

Saturday at 10:00PM

You need to recover the user’s documents to their most recent versions by

using the fewest number of backups.

Which backups should you restore?

Move/Match the required backups to the answer area place them in the

correct order.


"Day 5"

a)

Monday

b)

Tuesday

c)

Wednesday

d)

Thursday

e)

Friday

88.

A company backs up user data to the cloud by using this backup strategy

- A full back up every Sunday at 6:00PM

- An incremental back up every day except Sunday at 6:00PM

A user accidentally deleted their documents at 8:00AM Friday it is now

Saturday at 10:00PM

You need to recover the user’s documents to their most recent versions by

using the fewest number of backups.

Which backups should you restore?

Move/Match the required backups to the answer area place them in the

correct order.


"Day 6"

a)

Saturday

b)

Tuesday

c)

Wednesday

d)

Thursday

e)

Friday

89.

A company backs up user data to the cloud by using this backup strategy

- A full back up every Sunday at 6:00PM

- An incremental back up every day except Sunday at 6:00PM

A user accidentally deleted their documents at 8:00AM Friday it is now

Saturday at 10:00PM

You need to recover the user’s documents to their most recent versions by

using the fewest number of backups.

Which backups should you restore?

Move/Match the required backups to the answer area place them in the

correct order.


"Day 7"

a)

Saturday

b)

Sunday

c)

Wednesday

d)

Thursday

e)

Friday

90.

Analyze the following Console output from a Mac.

Based on this output, which event has occurred?

a)

A user has established an encrypted connection via a terminal

application

b)

A user is a victim of SYN flood attack

c)

A user is attempting a brute force attack

d)

A user has failed to establish an encrypted connection via a terminal

91.

Availability guarantees that systems, applications and data are accessible to

users when they need them.

a)

T

b)

F

92.

Confidentiality means that data or information on your system is maintained so that it is not modified or detected by unauthorized and parties.

a)

T

b)

F

93.

Integrity is the ability to protect data so that unauthorized parties cannot view it

a)

T

b)

F

94.

A network administrator has conducted a security adult and discovered that a

public IP address has been able to access the company’s private internal

network

a)

Have all users renew their DHCP address

b)

Update security software on all clients currently connected to the private network

c)

Update the IP address range for all computers on the internal network

d)

Block external IP addresses from the private network segment

95.

Destruction is one of the functions of the NIST Cybersecurity Destroy is one of

the functions of the NIST Cybersecurity

a)

T

b)

F

96.

Which command displays both the configured DNS server information and the

IP address resolution for a URL?

a)

NMap

b)

nslookup

c)

ping

d)

traceroute

97.

What are two disadvantages of public vulnerability databases (Choose 2)

a)

It can take a long time for reported vulnerabilities to be investigated and approved for addition to the databases

b)

Threat actors can access the databases to learn how to vary their threats to

avoid detection.

c)

Publicly available databases are incompatible with most security platforms

d)

It costly for intelligence analysts to document and submit newly discovered

vulnerabilities

98.

You find a USB Flash drive on the floor of the computer lab. You connect the

drive to your computer and antivirus warms you of a malware infection

a)

Vishing

b)

Whaling

c)

Phishing

d)

Baiting

99.

A network intrusion event is discovered at your company. You need to

diagram the intrusion by using the Diamond Model for intrusion analysis.

In the Diamond Model what does the Capability node represent?

a)

Network assets critical processes and customer data stored on the network

b)

IP addresses domain names and email addresses of the attack source

c)

People or organization initiating the intrusion in order to achieve a goal

d)

Malware tools and techniques used by the intruder during the attack

100.

You are collecting data after a suspected intrusion on the local LAN. You need to

capture incoming IP packets to a file for an investigator to analyze

Which two tools you use to achieve the goal? (Choose 2)

a)

TCPDump

b)

Wireshark

c)

Netstat

d)

NMap

101.

What security assessment of IT systems where PII data is available, accurate,

confidential, and accessible only by authorized personnel?

a)

Workflow Management

b)

Cyber Kill Chain

c)

Risk Framing

d)

Information Assurance

102.

Which encryption type is used to secure WIFI networks?

a)

RISA (Rivest Shamir Adleman)

b)

Advance Encryption Standard (AES)

c)

Data Encryption Standard

d)

Triple Data Encryption Standard (Triple DES)