WorksheetsSecurity Operations - 4.1 & 4.2
Total questions: 75
Worksheet time: 1hrs 15mins
1. Secure Baseline Implementation
After deploying new Windows workstations, the SOC notes that some users have local admin privileges.
What baseline control was likely missed?
A. Patch management
B. Least privilege configuration
C. Encryption enforcement
D. Application whitelisting
2. Baseline Maintenance
A server’s configuration drifts from the secure baseline over time due to manual updates.
What’s the best solution?
A. Increase patch frequency
B. Disable updates
C. Use configuration management tools (e.g., Ansible, SCCM)
D. Reimage the server weekly
3. Router Hardening
A network engineer enables SSH and disables Telnet on routers.
What principle is being applied?
A. Access control
B. Protocol hardening
C. Network segmentation
D. Default denial
4. Switch Hardening
An attacker connects to an unused switch port and gains network access.
What control prevents this?
A. VLAN tagging
B. Port security / MAC address limiting
C. Flood guards
D. QoS configuration
5. Server Hardening
A web server hosts only HTTPS but still allows TLS 1.0. What should be done?
A. Install more certificates
B. Enable HTTP/2
C. Disable weak cryptographic protocols
D. Add more firewall rules
6. Cloud Infrastructure Hardening
A cloud administrator leaves S3 buckets public by default.
Which control prevents this exposure?
A. Password complexity policy
B. Access control list (ACL) review and default deny
C. MFA enforcement
D. Role-based training
7. ICS/SCADA Security
A plant’s SCADA systems cannot be patched often due to uptime requirements.
What’s the best compensating control?
A. Network segmentation and strict access control
B. Annual reimaging
C. Full internet connectivity
D. Backup-only protection
8. IoT Device Hardening
IoT cameras in a building all use the default admin password.
What’s the best fix?
A. Limit network bandwidth
B. Change default credentials and update firmware
C. Use stronger Wi-Fi
D. Enable MAC filtering
9. Mobile Device Hardening
An employee’s phone is jailbroken.
What MDM policy should apply?
A. Enable roaming
B. Block access to corporate apps
C. Force strong password
D. Allow personal hotspot
10. RTOS Security
A vendor’s medical device runs an RTOS and cannot support antivirus.
What’s the best mitigation?
A. Install antivirus anyway
B. Implement strong network segmentation and monitoring
C. Apply host-based firewalls
D. Use TLS only
11. Establishing Secure Baselines
Which tool best automates establishing a Windows baseline?
A. Wireshark
B. Group Policy Objects (GPOs)
C. Ping
D. Nmap
12. Wireless Site Survey
During a new office setup, overlapping wireless channels cause poor performance.
What should have been done first?
A. Use WPA3
B. Perform a wireless site survey
C. Set static IPs
D. Enable SSID hiding
13. Heat Maps
The IT team uses a heat map showing signal strength across the building.
What is this map used for?
A. Incident response
B. Placement and coverage optimization
C. Bandwidth management
D. Guest network design
14. MDM Enforcement
If employees ignore password policies on their mobile devices, what can MDM enforce?
A. Nothing
B. Only notifications
C. Policy-based password compliance and remote wipe
D. VPN creation
15. BYOD Challenge
Which risk is highest in a BYOD deployment?
A. Data center downtime
B. Mixing personal and corporate data
C. VPN misconfiguration
D. Weak firewall
16. COPE Model
Which best describes Corporate-Owned, Personally Enabled (COPE)?
A. Employees bring their own phones
B. Company provides devices that can be used personally
C. Employees lease devices
D. Shared mobile pool
17. CYOD Deployment
In a CYOD program, what’s a major security benefit?
A. Employees pick any device
B. Devices remain preapproved and manageable by IT
C. Devices are unmanaged
D. Users install their own MDM
18. Wireless Security Setting
Which wireless security feature provides forward secrecy and resistance to offline dictionary attacks?
A. WPA2-PSK
B. WPA3-SAE (Simultaneous Authentication of Equals)
C. WEP
D. EAP-TLS
19. AAA Integration
Why would a company integrate wireless authentication with RADIUS?
A. Simplify passwords
B. Centralize AAA (Authentication, Authorization, Accounting)
C. Reduce encryption
D. Enable guest access
20. Cryptographic Protocol Choice
Which protocol provides the best security for wireless communication?
A. TKIP
B. WEP
C. AES-CCMP
D. MD5
21. Authentication Protocol
EAP-TLS provides which advantage?
A. Passwordless authentication using certificates
B. Simple username/password login
C. Shared key encryption
D. MAC filtering
22. Application Security
During testing, an app fails when given unexpected input. What control prevents this?
A. Encryption
B. Input validation
C. Authentication
D. Obfuscation
23. Secure Cookies
Why mark a cookie as “Secure” and “HttpOnly”?
A. Increases speed
B. Prevents interception and XSS attacks
C. Allows caching
D. Enables SSO
24. Static Code Analysis
A developer runs automated scanning before compiling. What is this process?
A. Dynamic analysis
B. Static code analysis
C. Fuzz testing
D. Runtime debugging
25. Code Signing
Why is code signing important?
A. Improves performance
B. Ensures code integrity and authenticity
C. Prevents zero-days
D. Enables debugging
26. Sandboxing
Developers test an unverified app in isolation. Which technique is used?
A. Patch testing
B. Sandboxing
C. Logging
D. Virtual patching
27. Monitoring
Which tool best identifies anomalies in baseline system behavior?
A. SIEM with behavioral analytics
B. IDS signatures only
C. Log rotation
D. Task scheduler
28. Secure Baseline Verification
After a Windows update, the baseline checksum file no longer matches.
What should be done?
A. Revalidate and update the baseline after integrity verification
B. Ignore differences
C. Restore old hash
D. Delete baseline
29. Mobile Connection Methods
Which mobile connection method introduces the most risk in public spaces?
A. Cellular
B. Open Wi-Fi
C. VPN
D. NFC
30. Bluetooth Security
Which setting prevents automatic Bluetooth connections to unknown devices?
A. Discoverable mode
B. Pairing approval or “ask before connecting”
C. Bluejacking
D. Beaconing
31. Cloud Monitoring
Which approach ensures compliance across multiple cloud environments?
A. Host-only monitoring
B. Cloud Security Posture Management (CSPM)
C. Local logging
D. Antivirus scanning
32. Secure Baseline Deployment
How can organizations deploy secure baselines efficiently across multiple VMs?
A. Use golden images
B. Manual setup
C. Ad hoc patching
D. Random provisioning
33. Workstation Hardening
Which control reduces attack surface on endpoints?
A. Disable antivirus
B. Application whitelisting
C. Enable guest accounts
D. Install more apps
34. Server Patch Prioritization
A zero-day affects a critical server. What should admins do?
A. Wait for baseline update
B. Apply vendor mitigation or isolate the system immediately
C. Ignore
D. Reboot
35. Embedded System Security
Smart vending machines use outdated firmware.
Best step?
A. Replace hardware
B. Apply vendor patches or restrict network access
C. Disable TLS
D. Use weaker encryption
36. Monitoring Wireless
Rogue access points appear in the office. Which tool detects this?
A. Ping
B. Wireless intrusion detection system (WIDS)
C. Firewall
D. DNS filter
37. Mobile Data Separation
How does an MDM enforce separation between work and personal data?
A. Containerization
B. Rooting
C. Jailbreaking
D. VPN tunneling
38. IoT Monitoring
What’s the best way to monitor IoT traffic for anomalies?
A. Network segmentation with flow analysis (NetFlow)
B. Install endpoint AV
C. Cloud-only scanning
D. Block all traffic
39. Application Security Failure
An application exposes stack traces to users during crashes.
Which control is missing?
A. Input validation
B. Error handling / exception management
C. Logging
D. Authentication
40. Secure Monitoring
Why use log normalization in SIEM systems?
A. Standardizes diverse log formats for correlation
B. Deletes duplicates
C. Speeds up storage
D. Encrypts data
41. Sandboxing in Email
Email attachments are detonated in a virtual machine before delivery.
What is this technique?
A. Whitelisting
B. Attachment sandboxing
C. Firewall filtering
D. Signature matching
42. Baseline Drift Detection
A file server’s registry differs from the baseline but has no recorded updates.
What’s the likely cause?
A. Patch installation
B. Unauthorized configuration change
C. Baseline error
D. Scheduled maintenance
43. Secure Wireless Deployment
To prevent unauthorized AP installations, what control helps?
A. WPA3 only
B. Network Access Control (NAC)
C. EAP-TLS
D. VLAN segmentation
44. Mobile App Vetting
Before allowing a new app on work devices, what’s the best security step?
A. Allow installation
B. Perform app reputation and permissions review
C. Test network speed
D. Ignore privacy policy
45. Cloud Hardening
Cloud admin discovers exposed management ports on virtual machines.
Best action?
A. Patch the OS
B. Restrict access using security groups/firewall rules
C. Add users
D. Reboot VMs
46. Monitoring Alerts
Analysts are overwhelmed by too many alerts.
What’s the best improvement?
A. Tune SIEM correlation rules and thresholds
B. Disable alerts
C. Ignore low-severity events
D. Use longer logs
47. Application Security Testing
A developer executes fuzzing against a running web app.
What is this?
A. Static testing
B. Dynamic application testing
C. Code review
D. Input sanitization
48. Router Monitoring
SNMPv2 is in use to monitor routers. What’s the risk?
A. High encryption
B. Unencrypted community strings (cleartext)
C. Performance degradation
D. VLAN mismatch
49. Server Baseline Compliance
Which tool automatically checks servers against CIS benchmarks?
A. Wireshark
B. SCAP compliance scanner
C. IDS
D. Packet sniffer
50. Continuous Hardening
How can organizations ensure hardening remains consistent after new deployments?
A. Manual audits
B. Automated compliance scanning and CI/CD integration
C. Random testing
D. Quarterly reboots
51. Procurement Oversight
A department orders new IoT sensors directly from a vendor without involving security review.
What’s the main risk?
A. Delayed delivery
B. Higher price
C. Introduction of unvetted or insecure hardware
D. Network congestion
52. Software Acquisition
A company purchases new CRM software without verifying its license type.
What’s a potential security implication?
A. Excessive logging
B. Use of pirated or unlicensed software lacking patches
C. Vendor lock-in
D. Slower installation
53. Procurement Process
Why should the security team participate in procurement?
A. To negotiate pricing
B. To reduce the vendor list
C. To ensure vendors meet security and compliance requirements
D. To speed up delivery
54. Hardware Ownership
Laptops are assigned to employees but not documented.
What risk does this create?
A. Device overheating
B. Lack of accountability and tracking
C. Network throttling
D. Double billing
55. Asset Classification
A project stores PII in the same shared folder as public data.
Which classification control failed?
A. Availability
B. Data segregation by sensitivity level
C. Encryption
D. Backup
56. Ownership Assignment
Why is assigning data ownership critical?
A. Reduces legal liability
B. Clarifies who is responsible for protection and access control
C. Allows more users
D. Simplifies backups
57. Asset Accounting
During an audit, 12 missing laptops aren’t found in inventory.
What’s the most likely process failure?
A. Improper logging
B. Poor asset accounting and tracking
C. Overclassification
D. Incorrect labeling
58. Asset Enumeration
A vulnerability scanner detects unknown systems on the network.
What does this indicate?
A. Rogue DHCP server
B. Untracked or unauthorized assets
C. Network segmentation
D. Misconfigured firewall
59. Monitoring and Tracking
What tool best supports hardware asset tracking?
A. IDS
B. CMDB
C. Firewall
D. Proxy
60. Data Classification
What’s the primary purpose of data classification?
A. To reduce redundancy
B. To determine security controls and handling procedures
C. To minimize storage
D. To simplify encryption
61. Software Inventory
A license compliance audit finds multiple unapproved applications installed by users.
What’s the likely cause?
A. Network latency
B. Lack of software whitelisting or inventory control
C. Weak password policy
D. Cloud misconfiguration
62. Asset Enumeration Techniques
What network security risk comes from poor asset enumeration?
A. Low bandwidth
B. Unmonitored devices that attackers can exploit
C. User lockouts
D. Duplicate IPs
63. Acquisition Policy
Why should all asset purchases go through a single procurement channel?
A. Simplifies payments
B. Ensures uniform security evaluation and recordkeeping
C. Minimizes network usage
D. Increases storage
64. Disposal Phase
Old hard drives are donated without wiping. What control failed?
A. Network segmentation
B. Encryption
C. Data sanitization before disposal
D. Physical access control
65. Sanitization Method
Which sanitization method is most appropriate for SSDs?
A. Low-level formatting
B. Cryptographic erasure
C. File deletion
D. Zero-fill overwriting
66. Destruction Verification
Why should destruction of storage media be certified?
A. Tax purposes
B. To prove compliance with legal or regulatory data retention standards
C. For shipping insurance
D. To reuse devices
67. Decommissioning Systems
Before decommissioning an old server, what should be done first?
A. Turn it off
B. Sanitize or migrate all stored data
C. Reinstall OS
D. Disable network
68. Data Retention
Why is a data retention policy important?
A. Reduces backups
B. Ensures legal, regulatory, and business obligations are met
C. Avoids encryption
D. Saves storage costs
69. Improper Retention
Old customer data kept past regulatory deadlines increases which risk?
A. Availability
B. Legal and privacy non-compliance
C. Data corruption
D. Backup failure
70. Certification Process
Which phase ensures that decommissioned hardware meets destruction standards?
A. Monitoring
B. Procurement
C. Disposal certification
D. Inventory enumeration
71. Software Asset Expiration
Expired licenses on security tools pose what threat?
A. Increased cost
B. Loss of updates and vulnerability exposure
C. Bandwidth reduction
D. Duplicate logs
72. Asset Lifecycle Security
What’s the best practice at each phase of the asset lifecycle?
A. Document only at disposal
B. Apply security controls from acquisition to destruction
C. Encrypt only at use
D. Ignore monitoring
73. Hardware Enumeration
Which method best validates the physical presence of assets?
A. SNMP polling
B. Physical inventory audit
C. Network scan
D. SIEM alert
74. Software Monitoring
To prevent shadow IT, admins deploy a tool that reports all executables on systems.
What’s this practice?
A. Software asset inventory and monitoring
B. Network mapping
C. Code review
D. Patch scanning
75. Data Ownership Conflict
Two departments share one database, both claiming ownership.
What’s the risk?
A. Redundant backups
B. Unclear accountability for security controls
C. Extra encryption
D. Better redundancy
