NEW
Font size
S
M
L
XL
WorksheetsMCyber_Chap24N25
Total questions: 21
Worksheet time: 21mins
Name
Class
Date
1.
What is the primary function of (ISC2)?
a)
To maintain a detailed list of all zero-day attacks
b)
To maintain a list of common vulnerabilities and exposures (CVE) used by prominent security organizations
c)
To provide vendor neutral education products and career services
d)
To provide a weekly digest of news articles about computer security
2.
What is the primary function of SANS?
a)
To maintain the Internet Storm Center
b)
To provide vendor neutral education products and career services
c)
To maintain the list of common vulnerabilities and exposures (CVE)
d)
To foster cooperation and coordination in information sharing, incident prevention, and rapid reaction
3.
What is the primary function of the Center for Internet Security (CIS)?
a)
To maintain a list of common vulnerabilities and exposures (CVE) used by security organizations
b)
To provide a security news portal that aggregates the latest breaking news pertaining to alerts, exploits, and vulnerabilities
c)
To offer 24×7 cyberthreat warnings and advisories, vulnerability identification, and mitigation and incident responses
d)
To provide vendor-neutral education products and career services to industry professionals worldwide
4.
What is the primary purpose of the Forum of Incident Response and Security Teams (FIRST)?
a)
To enable a variety of computer security incident response teams to collaborate, cooperate, and coordinate information sharing, incident prevention, and rapid reaction strategies
b)
To provide a security news portal that aggregates the latest breaking news pertaining to alerts, exploits, and vulnerabilities
c)
To offer 24×7 cyberthreat warnings and advisories, vulnerability identification, and mitigation and incident response
d)
To provide vendor neutral education products and career services to industry professionals worldwide
5.
Which service is offered by the U.S. Department of Homeland Security (DHS) that enables real-time exchange of cyberthreat indicators between the U.S. Federal Government and the private sector?
a)
AIS
b)
CVE
c)
STIX
d)
FireEye
6.
What does the MITRE Corporation create and maintain?
a)
IOC
b)
TAXII
c)
CVE
d)
STIX
7.
Which threat intelligence sharing open standard specifies, captures, characterizes, and communicates events and properties of network operations?
a)
CybOX
b)
Talos
c)
MISP
d)
TAXII
8.
What is the primary objective of a threat intelligence platform (TIP)?
a)
To provide a security operations platform that integrates and enhances diverse security tools and threat intelligence
b)
To aggregate the data in one place and present it in a comprehensible and usable format
c)
To provide a specification for an application layer protocol that allows the communication of CTI over HTTPS
d)
To provide a standardized schema for specifying, capturing, characterizing, and communicating events and properties of network operations
9.
How does FireEye detect and prevent zero-day attacks?
a)
By establishing an authentication parameter prior to any data exchange
b)
By addressing all stages of an attack lifecycle with a signature-less engine utilizing stateful attack analysis
c)
By keeping a detailed analysis of all viruses and malware
d)
By only accepting encrypted data packets that validate against their configured hash values
10.
Which service is provided by the Cisco Talos Group?
a)
Preventing online malware from affecting end user devices
b)
Preventing viruses from affecting end user devices
c)
Collecting information about active, existing, and emerging threats
d)
Scanning updates for malware code
11.
In profiling a server, what defines what an application is allowed to do or run on a server?
a)
User accounts
b)
Listening ports
c)
Service accounts
d)
Software environment
12.
In network security assessments, which type of test is used to evaluate the risk posed by vulnerabilities to a specific organization including assessment of the likelihood of attacks and the impact of successful exploits on the organization?
a)
Port scanning
b)
Rsk analysis
c)
Penetration testing
d)
Vulnerability assessment
13.
When a network baseline is being established for an organization, which network profile element indicates the time between the establishment of a data flow and its termination?
a)
Session duration
b)
Critical asset address space
c)
Ports used
d)
Total throughput
14.
Which type of evaluation includes the assessment of the likelihood of an attack, the type of threat actor likely to perpetrate such an attack, and what the consequences could be to the organization if the exploit is successful?
a)
Penetration testing
b)
Risk analysis
c)
Vulnerability identification
d)
Server profiling
15.
A cybersecurity analyst is performing a CVSS assessment on an attack where a web link was sent to several employees. Once clicked, an internal attack was launched. Which CVSS Base Metric Group Exploitability metric is used to document that the user had to click on the link in order for the attack to occur?
a)
Scope
b)
Integrity requirement
c)
Availability requirement
d)
User interaction
16.
Which metric class in the CVSS Basic Metric Group identifies the impacts on confidentiality, integrity, and availability?
a)
Exploitability
b)
Modified Base
c)
Impact
d)
Exploit Code Maturity
17.
Which metric in the CVSS Base Metric Group is used with an attack vector?
a)
The determination whether the initial authority changes to a second authority during the exploit
b)
The presence or absence of the requirement for user interaction in order for an exploit to be successful
c)
The proximity of the threat actor to the vulnerability
d)
The number of components, software, hardware, or networks, that are beyond the control of the attacker and that must be present in order for a vulnerability to be successfully exploited
18.
Which statement describes the threat-vulnerability (T-V) pairing?
a)
It is the identification of threats and vulnerabilities and the matching of threats with vulnerabilities.
b)
It is the comparison between known malware and system risks.
c)
It is the detection of malware against a central vulnerability research center.
d)
It is the advisory notice from a vulnerability research center.
19.
In addressing an identified risk, which strategy aims to shift some of the risk to other parties?
a)
Risk avoidance
b)
Risk reduction
c)
Risk retention
d)
Risk sharing
20.
Which step in the Vulnerability Management Life Cycle categorizes assets into groups or business units, and assigns a business value to asset groups based on their criticality to business operations?
a)
Report
b)
Assess
c)
Remediate
d)
Prioritize assets
21.
What is an action that should be taken in the discovery step of the vulnerability management life cycle?
a)
Documenting the security plan
b)
Assigning business value to assets
c)
Developing a network baseline
d)
Determining a risk profile
Reset
