wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

MCyber_Chap20N21

Total questions: 24

Worksheet time: 24mins

Name
Class
Date
1.
Which type of security data can be used to describe or predict network behavior?
a)
Alert
b)
Session
c)
Statistical
d)
Transaction
2.
Which Windows tool can be used to review host logs?
a)
Services
b)
Event Viewer
c)
Task Manager
d)
Device Manager
3.
What are two popular SIEM platforms? (Choose two.)
a)
Splunk
b)
Netflow
c)
Tcpdump
d)
Cisco Umbrella
e)
Security Onion with ELK
4.
What is a feature of the tcpdump tool?
a)
It records metadata about packet flows.
b)
It uses agents to submit host logs to centralized management servers.
c)
It can display packet captures in real time or write them to a file.
d)
It provides real-time reporting and long-term analysis of security events.
5.
Which type of data is used by Cisco Cognitive Intelligence to find malicious activity that has bypassed security controls, or entered through unmonitored channels, and is operating inside an enterprise network?
a)
Statistical
b)
Session
c)
Alert
d)
Transaction
6.
What are two of the 5-tuples? (Choose two.)
a)
IPS
b)
Source port
c)
IDS
d)
ACL
e)
Protocol
7.
Which statement describes the tcpdump tool?
a)
It is a command line packet analyzer.
b)
It is used to control multiple TCP-based applications
c)
It accepts and analyzes data captured by Wireshark.
d)
It can be used to analyze network log data in order to describe and predict network behavior.
8.
Which Windows host log event type describes the successful operation of an application, driver, or service?
a)
Error
b)
Warning
c)
Information
d)
Success Audit
9.
Which statement describes an operational characteristic of NetFlow?
a)
NetFlow collects basic information about the packet flow, not the flow data itself.
b)
NetFlow captures the entire contents of a packet.
c)
NetFlow flow records can be viewed by the tcpdump tool.
d)
NetFlow can provide services for user access control.
10.
Which Windows log records events related to login attempts and operations related to file or object access?
a)
Setup logs
b)
Security logs
c)
Application logs
d)
System logs
11.
In a Cisco AVC system, in which module is NBAR2 deployed?
a)
Control
b)
Metrics Collection
c)
Application Recognition
d)
Management and Reporting
12.
A NIDS/NIPS has identified a threat. Which type of security data will be generated and sent to a logging device?
a)
Alert
b)
Session
c)
Statistical
d)
Transaction
13.
What is the host-based intrusion detection tool that is integrated into Security Onion?
a)
OSSEC
b)
Snort
c)
Sguil
d)
Wireshark
14.
Which tool is included with Security Onion that is used by Snort to automatically download new rules?
a)
Sguil
b)
Wireshark
c)
ELSA
d)
PulledPork
15.
Which tool included in Security Onion is an interactive dashboard interface to Elasticsearch data?
a)
Sguil
b)
Zeek
c)
Kibana
d)
Wireshark
16.
Which NIDS tool uses a signature-based approach and native multithreading for alert detection?
a)
Snort
b)
Bro
c)
Zeek
d)
Suricata
17.
Which tool is a Security Onion integrated host-based intrusion detection system?
a)
Wazuh
b)
Suricata
c)
Snort
d)
Zeek
18.
What are three analysis tools that are integrated into Security Onion? (Choose three.)
a)
Snort
b)
Sguil
c)
OSSEC
d)
Kibana
e)
Wireshark
19.
What function is provided by Snort as part of the Security Onion?
a)
To view pcap transcripts generated by intrusion detection tools
b)
To generate network intrusion alerts by the use of rules and signatures
c)
To normalize logs from various NSM data logs so they can be represented, stored, and accessed through a common schema
d)
To display full-packet captures for analysis
20.
What classification is used for an alert that correctly identifies that an exploit has occurred?
a)
False negative
b)
False positive
c)
True positive
d)
True negative
21.
Which type of analysis relies on predefined conditions and can analyze applications that only use well-known fixed ports?
a)
Statistical
b)
Deterministic
c)
Log
d)
Probabilistic
22.
Which type of analysis relies on different methods to establish the likelihood that a security event has happened or will happen?
a)
Deterministic
b)
Statistical
c)
Log
d)
Probabilistic
23.
Which alert classification indicates that exploits are not being detected by installed security systems?
a)
False negative
b)
True negative
c)
True positive
d)
False positive
24.
Which tool would an analyst use to start a workflow investigation?
a)
ELSA
b)
Bro
c)
Sguil
d)
Snort