Font size
WorksheetsIT23L Review 6,7,-8
Total questions: 102
Worksheet time: 53mins
Which activity by anniversary is an example of an exploit that is attempting to gain
user credentials?
Installing a backdoor in order to enable two way communication with the device
Obtaining a directory listing of files located on the web date database server
Sending an email with a link to a fictitious web portal login page
Executing a remote port scan of all the enterprise registered IP addresses
You are monitoring the syslog server and observe that the dns server is sending
messages with a warning severity. what do these messages indicate about the
operation of the dns server?
The server has a hardware error that does not require immediate attention
An error condition is occurring that must be
addressed immediately
Condition exists that will cause errors in the future if the issue is not fixed
The DNS server is unusable due to a severe malfunction and is shutting down.
What is the purpose of a hypervisor?
It monitors and logs network traffic for malicious pockets
It creates and runs virtual machines
It provides and monitors firewall services for
cloud computing
It provides and services a gateway between users and the internet
What you should create to prevent spoofing of the internal network?
A DNS Record
an ACL (access control list)
A Net Rule
A Record In the Host File
What mitigate the impact of the incident?
Containment, Eradication, And Recovery
Post-incident activity and preparation
Detection and Analysis
Preparation
What reports, the cause and cost of the incident and the steps to prevent future incidents.
Containment, Eradication, And Recovery
Post-incident activity and preparation
Detection and Analysis
Preparation
What evaluate incident indicators to determine whether they are legitimate attacks and alerts the organization of the incident?
Containment, Eradication, And Recovery
Post-incident activity and preparation
Detection and Analysis
Preparation
What establishes an incident response capability to ensure that organizational assets are sufficiently secure?
Containment, Eradication, And Recovery
Post-incident activity and preparation
Detection and Analysis
Preparation
We need to filter the websites that are available to employees on the company
network. which type of device should you deploy?
IDS
IPS
PROXY SERVER
HONEY POT
Match the correct answer.
People, Property, Or Data
Asset
Risk
Threat
Vulnerability
Match the correct answer.
An Action that Causes Negative Impact
Asset
Risk
Threat
Vulnerability
Match the correct answer.
The Potential For Loss, Damage Or Destruction
Asset
Risk
Threat
Vulnerability
Match the correct answer.
The weakness that potentially exposes
Organizations for cyber attacks are:
Asset
Risk
Threat
Vulnerability
Which wireless encryption technology requires AES to secure home wireless
networks?
WPA3
TKIP
WEP
WPA2
A corporation hires a group of experienced cyber criminals to create a prolonged and in-depth presthis presence will allow corporations to steal or sabotage sensitive data from their competitors. whdescribe?
Man in the Middle
APT (Advanced Persistent Threat)
DDOS
Ransomware
A security analyst may use a disgruntled employee's network credentials to monitor
behavior.
True
False
So what contains events that are received from programs running on the
device?
Application Logs
Setup Logs
System Logs
Security Logs
Record information about software installation and operating system updates.
Application Logs
Setup Logs
System Logs
Security Logs
List events generated by the operation of hardware, drivers and processes.
Application Logs
Setup Logs
System Logs
Security Logs
Record the success or failure of the audit
policy events
Application Logs
Setup Logs
System Logs
Security Logs
After an administrator installs an operating system update on a laptop, the laptop
user can no longer print to their wireless printer. what should solve the issue?
Install a new device driver for the wireless printer
Update the firmware on the laptop
Reinstall the same service
pack
Check for patches for wireless printers
Your organization as IEM system alerts you that users are connecting to an unusual
url. you need to determine whether the URL is malicious and what type of threat it
represents. what should you do?
Visit the URL to determine whether the website is legitimate
Ask users why they visited the website
Submit the URL to the threat intelligence portal for analysis
block the URL by placing it on the network block
list.
Which activity is an example of active
recognition performed during a penetration test?
Search the who's database for the owner and technical contact information for a
domain
Gathering employees
information from available web directories and social media
Perform an NMAP port scan on the LAN to determine the types of
connected devices and open ports
Using a browser to view the
http source code of company web pages
What are two natural disasters that would use a company to implement a disaster
recovery plan? choose two.
Nuclear Contamination
Hazardous Material Spills
Floods
Volcanic Eruptions
Customers of an online shopping store are complaining that they cannot visit the
website. as an it technician, you restart the website. after 30 minutes, the website
crashes again. you suspect that the website has experienced a cyber attack. so which
type of cyber security threat should you investigate?
Ransomware
Denial of Service (Dos)
Spear Phishing
Social Engineering
What enables the network security team to keep track of the operating system
versions, security updates and patches on end user devices?
Incident Management
Business Continuity Planning
Asset Management
Security Policies and
Procedures
Which two basic metrics should be taken into consideration when assigning a
severity to a vulnerability during an assessment? choose two
The impacts that exploitation of the vulnerability will have on the
organization
The time involved in choosing replacement software to replace older system
The age of the hardware running the software that contains vulnerability
The likelihood that an adversary can and will exploit the vulnerability
in order to do online banking, enter a strong password and then enter the 5 digit
code sent to you on your smartphone. What type of authentication does this
situation
description.
Radius
VPN
Multifactor Authentication
Triple
A cybersecurity analyst is investigating an unknown executable file discovered a
linux desktop computer. the analyst enters the
following command in the terminal . What is the purpose of this command
To display the content of a
text file.
Navigate to the folder that is passed as an argument to the command.
, To display the file permissions and ownership of the executable file.
To open a text editor
Security analysts may have access to employee data on the company server, if
authorized.
True
False
You work for a community healthcare organization that uses an electronic health
record system. you have implemented the physical and technical safeguards
required by HIPAA. you need to prove that the system is compliant with those
safeguards. which two approaches should you use to verify that the system is
compliant? choose two.
It Auditing
Penetration Testing
Automatic Log off Implementation
Security Awareness Training
What does hashing provide for data communication
Data Encryption
Data Non Repudiation
Origin Authentication.
Data Integrity
Match the Correct answer.
NESSUS SCANNER
CVSS (COMMON VULNERABILITY SCORING SYSTEM)
Discovering
Prioritizing
Remediating
Match the Correct answer.
NMAP
Discovering
Prioritizing
Remediating
Match the Correct answer.
PATCH MANAGEMENT SOFTWARE WINDOWS AUTO UPDATE AND PATCH
Discovering
Prioritizing
Remediating
A security analyst may share sensitive
data with unauthorized users
True
False
You are reviewing the company's remote access procedures and noticed that telnet
is being used to connect to a corporate database server. to check on inventory levels,
which two actions should you take immediately? choose two
Reconfigure the server to only accept http connections
Force users to implement secure telnet passwords.
Disable telnet access on the server
Implement SSH access on the server
A system on your network is experiencing slower than usual response times. in
order to gather information about the status of the system, you issue a netstat minus
1 command to display all the TCP ports that are in the listening state. what does the
listening state indicate about these ports?
The ports are actively connected to another system or process
Remote and disconnected and the ports are closing
The ports are open on the system and are waiting for connections
The state of the connection on the ports is
unknown
You are a security technician. you just completed a full scan of a windows 10 pc.
where should you go to view the scan results?
Windows System logs
Windows Application Logs
Windows Security
Windows Task Manager
Several staff members are experiencing unexplained computer crashes and many
unwanted popup messages. which 2 actions should you take immediately to address
the problem without impacting data? choose two.
Deploy a policy to install and automatically upgrade antivirus and antimalware software
Reinstall windows on the affected workstations
Scan affected workstations and remove malware
Configure the network firewall to block
malware from entering the internal network.
A security analyst discovers that a hacker was able to gain root access to an
enterprise linux server. the hacker accessed the server as a guest and used a
program to bypass the root
password, and then killed essential server processes as the root user. which type of
endpoint attack is this?
Buffer Overflow
Boot Force
DDOS
Privilege escalation.
What are the two disadvantages of public vulnerability databases? choose 2.
It is costly for intelligence analysts to document and submit
newly discovered vulnerabilities
It can take a long time for reported vulnerabilities to be investigated and
approved for addition to the databases
Publicly available databases are incompatible with most security platforms
Threat actors can access the databases to learn how to vary the threats to
avoid detection
Match the correct answer
Discover unwanted events
Detective Measures
Preventive Measures
Corrective Measures
Match the correct answer
Avert the occurrence of an event.
Detective Measures
Preventive Measures
Corrective Measures
Match the correct answer
Restore a system after the event
Detective Measures
Preventive Measures
Corrective Measures
Several employees complained that the company's intranet site is no longer
accepting their login information. you attempt to connect using
the url and noticed some misspellings on the site. when you connect using the IP
address, the site functions normally. what should you do?
Update the web server software to the latest version
Restore about a backup copy of the authentication database
Verify the accuracy of the entry for the site in the local DNS server
Take the company web portal offline immediately.
You are security analyst. you are reviewing the output from siem. You will notice an
alert concerning malicious files detected by IDs. after reviewing the user's device
and posture information, you have determined that it is a valid incident. what
should you do next?
Log the alert and watch for a second occurrence.
Escalate The Situation Immediately.
update the documentation to include the new alert information.
Prepare Notes To Present At The Weekly Cyber Security Team Meeting.
Yes or No if its typical located in company's demilitarized zone:
Directory
Yes
No
Yes or No if its typical located in company's demilitarized zone:
Yes
No
Yes or No if its typical located in company's demilitarized zone:
Web
Yes
No
Yes or No if its typical located in company's demilitarized zone:
Yes
No
Yes or No if its typical located in company's demilitarized zone:
Zenmap is a GUI app that runs nmap.
Yes
No
Yes or No if its typical located in company's demilitarized zone:
ss is the Linux equivalent of netstat.
Yes
No
Yes or No if its typical located in company's demilitarized zone:
netstat runs in a GUI environment.
Yes
No
Yes or No if its typical located in company's demilitarized zone:
netstat shows active and waiting ports for connections.
Yes
No
In a DHCP ___________attack, threat actors configure a fake DHCP server on the
network to issue DHCP addresses to clients.
Rogue DHCP Attack
DHCP Starvation Attack
DNS Amplification Attack
DNS Spoofing Attack
In a DHCP __________attack, threat actors flood the DHCP server with DHCP requests to use up all the available IP addresses that the legitimate DHCP server can issue.
Rogue DHCP Attack
DHCP Starvation Attack
DNS Amplification Attack
DNS Spoofing Attack
In a DNS __________attack, threat actors use publicly accessible open DNS servers to flood a target with DNS response traffic
Rogue DHCP Attack
DHCP Starvation Attack
DNS Amplification Attack
DNS Spoofing Attack
In a DNS ___________attack, threat actors change the A record for your domain’s IP address to point to a predetermined address of their choice.
Rogue DHCP Attack
DHCP Starvation Attack
DNS Amplification Attack
DNS Spoofing Attack
Match the answer.
The condition should be corrected immediately.
Leve 1 (Alert)
Level 4 (Warning)
Level 5 (Notice)
Level 6 (Informational)
Match the answer.
An error may occur if the situation is not remedied.
Leve 1 (Alert)
Level 4 (Warning)
Level 5 (Notice)
Level 6 (Informational)
Match the answer.
Unusual event but not an error.
Leve 1 (Alert)
Level 4 (Warning)
Level 5 (Notice)
Level 6 (Informational)
Match the answer.
Normal operation. The situation requires no intervention.
Leve 1 (Alert)
Level 4 (Warning)
Level 5 (Notice)
Level 6 (Informational)
Threat actors send emails randomly to a very large number of recipients with
the intent to gather information for fraud or identity theft.
Phishing
Smishing
Vishing
Threat actors send emails that are carefully designed to get a single recipient within an organization to respond and unknowingly install malware onto their system
Phishing
Smishing
Vishing
Threat actors create fraudulent text messages to try to lure victims into revealing account information or installing malware
Phishing
Smishing
Vishing
Threat actors use voice calls to manipulate an individual into releasing confidential data.
Phishing
Smishing
Vishing
Hardened facilities and alternate sites.
Natural Disasters
Cyberattack
Supply-Chain Disruptions
Employee Errors
Firewalls, IDS and IPS, and Log Analyzers.
Natural Disasters
Cyberattack
Supply-Chain Disruptions
Employee Errors
Alternate sources, and inventory management
Natural Disasters
Cyberattack
Supply-Chain Disruptions
Employee Errors
Standard procedures, and training
Natural Disasters
Cyberattack
Supply-Chain Disruptions
Employee Errors
You need to implement a multifactor authentication system for physical
access to a building. You are currently using only a fingerprint scan.
Retinal Scan
Facial Recognition
Voiceprint Analysis
ID Card
Recover is one of the core functions of the NIST Cybersecurity
True
False
Protects the personal information of members of the European Union
GDPR (General Data Protection Regulation)
HIPAA (Health Insurance Portability and Accountability Act)
PCI-DSS (Payment Card Industry Data Security Standard)
FERPA (Family Educational Rights and Privacy Act)
FISMA (Federal Information Security Management Act)
Protects the healthcare information of individuals
GDPR (General Data Protection Regulation)
HIPAA (Health Insurance Portability and Accountability Act)
PCI-DSS (Payment Card Industry Data Security Standard)
FERPA (Family Educational Rights and Privacy Act)
FISMA (Federal Information Security Management Act)
Protects the credit card information of individuals
GDPR (General Data Protection Regulation)
HIPAA (Health Insurance Portability and Accountability Act)
PCI-DSS (Payment Card Industry Data Security Standard)
FERPA (Family Educational Rights and Privacy Act)
FISMA (Federal Information Security Management Act)
Protects the educational records of individuals
GDPR (General Data Protection Regulation)
HIPAA (Health Insurance Portability and Accountability Act)
PCI-DSS (Payment Card Industry Data Security Standard)
FERPA (Family Educational Rights and Privacy Act)
FISMA (Federal Information Security Management Act)
Protects information about individuals that is stored by federal agencies
GDPR (General Data Protection Regulation)
HIPAA (Health Insurance Portability and Accountability Act)
PCI-DSS (Payment Card Industry Data Security Standard)
FERPA (Family Educational Rights and Privacy Act)
FISMA (Federal Information Security Management Act)
Detects network connections routing tables interface statistics
masquerade connections and multicast membership
netstat
NMap
nslookup
Scans networks for open ports service versions and operating system information
netstat
NMap
nslookup
Performs DNS queries to obtain domain name of IP address mapping information
netstat
NMap
nslookup
Respond is more of the functions of the NIST Security Framework
True
False
A company backs up user data to the cloud by using this backup strategy
- A full back up every Sunday at 6:00PM
- An incremental back up every day except Sunday at 6:00PM
A user accidentally deleted their documents at 8:00AM Friday it is now
Saturday at 10:00PM
You need to recover the user’s documents to their most recent versions by
using the fewest number of backups.
Which backups should you restore?
Move/Match the required backups to the answer area place them in the
correct order.
"Day 1"
Monday
Tuesday
Wednesday
Thursday
Friday
A company backs up user data to the cloud by using this backup strategy
- A full back up every Sunday at 6:00PM
- An incremental back up every day except Sunday at 6:00PM
A user accidentally deleted their documents at 8:00AM Friday it is now
Saturday at 10:00PM
You need to recover the user’s documents to their most recent versions by
using the fewest number of backups.
Which backups should you restore?
Move/Match the required backups to the answer area place them in the
correct order.
"Day 2"
Monday
Tuesday
Wednesday
Thursday
Friday
A company backs up user data to the cloud by using this backup strategy
- A full back up every Sunday at 6:00PM
- An incremental back up every day except Sunday at 6:00PM
A user accidentally deleted their documents at 8:00AM Friday it is now
Saturday at 10:00PM
You need to recover the user’s documents to their most recent versions by
using the fewest number of backups.
Which backups should you restore?
Move/Match the required backups to the answer area place them in the
correct order.
"Day 3"
Monday
Tuesday
Wednesday
Thursday
Friday
A company backs up user data to the cloud by using this backup strategy
- A full back up every Sunday at 6:00PM
- An incremental back up every day except Sunday at 6:00PM
A user accidentally deleted their documents at 8:00AM Friday it is now
Saturday at 10:00PM
You need to recover the user’s documents to their most recent versions by
using the fewest number of backups.
Which backups should you restore?
Move/Match the required backups to the answer area place them in the
correct order.
"Day 4"
Monday
Tuesday
Wednesday
Thursday
Friday
A company backs up user data to the cloud by using this backup strategy
- A full back up every Sunday at 6:00PM
- An incremental back up every day except Sunday at 6:00PM
A user accidentally deleted their documents at 8:00AM Friday it is now
Saturday at 10:00PM
You need to recover the user’s documents to their most recent versions by
using the fewest number of backups.
Which backups should you restore?
Move/Match the required backups to the answer area place them in the
correct order.
"Day 5"
Monday
Tuesday
Wednesday
Thursday
Friday
A company backs up user data to the cloud by using this backup strategy
- A full back up every Sunday at 6:00PM
- An incremental back up every day except Sunday at 6:00PM
A user accidentally deleted their documents at 8:00AM Friday it is now
Saturday at 10:00PM
You need to recover the user’s documents to their most recent versions by
using the fewest number of backups.
Which backups should you restore?
Move/Match the required backups to the answer area place them in the
correct order.
"Day 6"
Saturday
Tuesday
Wednesday
Thursday
Friday
A company backs up user data to the cloud by using this backup strategy
- A full back up every Sunday at 6:00PM
- An incremental back up every day except Sunday at 6:00PM
A user accidentally deleted their documents at 8:00AM Friday it is now
Saturday at 10:00PM
You need to recover the user’s documents to their most recent versions by
using the fewest number of backups.
Which backups should you restore?
Move/Match the required backups to the answer area place them in the
correct order.
"Day 7"
Saturday
Sunday
Wednesday
Thursday
Friday
Analyze the following Console output from a Mac.
Based on this output, which event has occurred?
A user has established an encrypted connection via a terminal
application
A user is a victim of SYN flood attack
A user is attempting a brute force attack
A user has failed to establish an encrypted connection via a terminal
Availability guarantees that systems, applications and data are accessible to
users when they need them.
T
F
Confidentiality means that data or information on your system is maintained so that it is not modified or detected by unauthorized and parties.
T
F
Integrity is the ability to protect data so that unauthorized parties cannot view it
T
F
A network administrator has conducted a security adult and discovered that a
public IP address has been able to access the company’s private internal
network
Have all users renew their DHCP address
Update security software on all clients currently connected to the private network
Update the IP address range for all computers on the internal network
Block external IP addresses from the private network segment
Destruction is one of the functions of the NIST Cybersecurity Destroy is one of
the functions of the NIST Cybersecurity
T
F
Which command displays both the configured DNS server information and the
IP address resolution for a URL?
NMap
nslookup
ping
traceroute
What are two disadvantages of public vulnerability databases (Choose 2)
It can take a long time for reported vulnerabilities to be investigated and approved for addition to the databases
Threat actors can access the databases to learn how to vary their threats to
avoid detection.
Publicly available databases are incompatible with most security platforms
It costly for intelligence analysts to document and submit newly discovered
vulnerabilities
You find a USB Flash drive on the floor of the computer lab. You connect the
drive to your computer and antivirus warms you of a malware infection
Vishing
Whaling
Phishing
Baiting
A network intrusion event is discovered at your company. You need to
diagram the intrusion by using the Diamond Model for intrusion analysis.
In the Diamond Model what does the Capability node represent?
Network assets critical processes and customer data stored on the network
IP addresses domain names and email addresses of the attack source
People or organization initiating the intrusion in order to achieve a goal
Malware tools and techniques used by the intruder during the attack
You are collecting data after a suspected intrusion on the local LAN. You need to
capture incoming IP packets to a file for an investigator to analyze
Which two tools you use to achieve the goal? (Choose 2)
TCPDump
Wireshark
Netstat
NMap
What security assessment of IT systems where PII data is available, accurate,
confidential, and accessible only by authorized personnel?
Workflow Management
Cyber Kill Chain
Risk Framing
Information Assurance
Which encryption type is used to secure WIFI networks?
RISA (Rivest Shamir Adleman)
Advance Encryption Standard (AES)
Data Encryption Standard
Triple Data Encryption Standard (Triple DES)
