wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

MCyber_Chap26N27

Total questions: 23

Worksheet time: 23mins

Name
Class
Date
1.
A user is asked to perform a risk analysis of a company. The user asks for the company asset database that contains a list of all equipment.The user uses this information as part of a risk analysis. Which type of risk analysis could be performed?
a)
Exposure factor
b)
Hardware
c)
Quantitative
d)
Qualitative
2.
Which two types of controls are effective after a violation of a security policy occurs? (Choose two.)
a)
Corrective
b)
Preventive
c)
Recovery
d)
Deterrent
e)
Compensative
3.
Which type of security control includes backup and restore operations, as well as fault-tolerant data storage?
a)
Deterrent
b)
Recovery
c)
Detection
d)
Compensative
4.
The CEO of a company is concerned that if a data breach should occur and customer data is exposed, the company could be sued. The CEO makes the decision to buy insurance for the company. What type of risk mitigation is the CEO implementing?
a)
Avoidance
b)
Mitigation
c)
Transference
d)
Reduction
5.
A warning banner that lists the negative outcomes of breaking company policy is displayed each time a computer user logs in to the machine. What type of access control is implemented?
a)
Masking
b)
Deterrent
c)
Detective
d)
Preventive
6.
Which access control should the IT department use to restore a system back to its normal state?
a)
Compensative
b)
Preventive
c)
Corrective
d)
Detective
7.
Based on the risk management process, what should the cybersecurity team do as the next step when a cybersecurity risk is identified?
a)
Frame the risk
b)
Monitor the risk.
c)
Respond to the risk.
d)
Assess the risk
8.
What is the first step in the risk management process that helps to reduce the impact of threats and vulnerabilities?
a)
Frame the risk
b)
Assess the risk
c)
Monitor the risk
d)
Respond to the risk
9.
A public cloud service company provides data storage services to multiple customers. The company decides to purchase an insurance policy to cover the data loss due to natural disasters. Which risk management action level has the service company taken to manage the potential risk?
a)
Accept
b)
Transfer
c)
Mitigation
d)
Avoidance
10.
Which statement describes a cybersecurity risk?
a)
It is a weakness in information systems
b)
It is a threat which causes loss of assets
c)
It is the probability of loss due to a threat
d)
It is the damage incurred by an event which causes disruption of network services
11.
A user is asked to evaluate the security posture of a company. The user looks at past attempts to break into the company and evaluates the threats and exposures to create a report. Which type of risk analysis could the user perform?
a)
Subjective
b)
Opinion
c)
Qualitative
d)
Objective
12.
According to NIST, which step in the digital forensics process involves drawing conclusions from data?
a)
Reporting
b)
Collection
c)
Examination
d)
Analysis
13.
Which term is used in the Diamond Model of intrusion to describe a tool that a threat actor uses toward a target system?
a)
Infrastructure
b)
Capability
c)
Weaponization
d)
Adversary
14.
Which statement describes the Cyber Kill Chain?
a)
It identifies the steps that adversaries must complete to accomplish their goals.
b)
It specifies common TCP/IP protocols used to fight against cyberattacks
c)
It is a set of metrics designed to create a way to describe security incidents in a structured and repeatable way
d)
It uses the OSI model to describe cyberattacks at each of the seven layers
15.
Which meta-feature element in the Diamond Model describes tools and information (such as software, black hat knowledge base, and username and password) that the adversary uses for the intrusion event?
a)
Results
b)
Direction
c)
Resources
d)
Methodology
16.
What is the purpose of the policy element in a computer security incident response capability of an organization, as recommended by NIST?
a)
It provides a roadmap for maturing the incident response capability
b)
It provides metrics for measuring the incident response capability and effectiveness
c)
It defines how the incident response teams will communicate with the rest of the organization and with other organizations
d)
It details how incidents should be handled based on the organizational mission and functions
17.
The company you work for has asked you to create a broad plan that includes DRP and getting critical systems to another location in case of disaster. What type of plan are you being asked to create?
a)
Annual loss expectancy
b)
Network Admission Control
c)
Business continuity plan
d)
Disaster recovery plan
18.
Which action should be included in a plan element that is part of a computer security incident response capability (CSIRC)?
a)
Detail how incidents should be handled based on the mission and functions of an organization
b)
Develop metrics for measuring the incident response capability and its effectiveness
c)
Create an organizational structure and definition of roles, responsibilities, and levels of authority
d)
Prioritize severity ratings of security incidents
19.
What is a MITRE ATT&CK framework?
a)
A collection of malware exploits and prevention solutions
b)
A knowledge base of threat actor behavior
c)
Guidelines for the collection of digital evidence
d)
Documented processes and procedures for digital forensic analysis
20.
Which two actions can help identify an attacking host during a security incident? (Choose two.)
a)
Use an Internet search engine to gain additional information about the attack
b)
Log the time and date that the evidence was collected and the incident remediated
c)
Determine the location of the recovery and storage of all evidence
d)
Validate the IP address of the threat actor to determine if it is viable
e)
Develop identifying criteria for all evidence such as serial number, hostname, and IP address
21.
A threat actor has gained administrative access to a system and achieved the goal of controlling the system for a future DDoS attack by establishing a communication channel with a CnC owned by the threat actor. Which phase in the Cyber Kill Chain model describes the situation?
a)
Delivery
b)
Exploitation
c)
Command and control
d)
Action on objectives
22.
A user is asked to create a disaster recovery plan for a company. The user needs to have a few questions answered by management to proceed. Which three questions should the user ask management as part of the process of creating the plan? (Choose three.)
a)
Who is responsible for the process
b)
What is the process?
c)
Does the process require approval?
d)
How long does the process take?
e)
Where does the individual perform the process?
23.
After containing an incident that infected user workstations with malware, what are three effective remediation procedures that an organization can take for eradication? (Choose three.)
a)
Change assigned names and passwords for all devices.
b)
Update and patch the operating system and installed software of all hosts.
c)
Rebuild hosts with installation media if no backups are available
d)
Rebuild DHCP servers using clean installation media.
e)
Use clean and recent backups to recover hosts