Font size
WorksheetsCybersecurity Certification
Total questions: 61
Worksheet time: 31mins
A system on your network is experiencing slower than usual response times. In order to gather information about the status of the system, you issue the netstat =l command to display all of the TCP ports that are in the listing state. What does the Listening state indicate about these ports?
The state of the connection on the ports is unknown.
The remote end disconnected and the ports are closing.
The ports are open on the system and are waiting for connections.
The ports are actively connected to another system or process.
Match each NIST incident response lifecycle phase to its correct description:
1. Mitigate the impact of the incident
2. Report the cause and cost of the incident and the steps to prevent future incidents
3. Evaluates incident indicators to determine whether they are legitimate attacks and alerts the organization of the incidents
4. Establishes an incident response capability to ensure that organizational assets are sufficiently secure
Preparation,
Post-incident Activity, Detection and Analysis, Containment,
Eradication, and Recovery
Detection and Analysis, Preparation, Containment, Eradication, and Recovery, Post-incident Activity
Containment, Eradication, and Recovery, Post-incident Activity, Detection and Analysis, Preparation
Preparation, Detection and Analysis, Containment, Eradication, and Recovery, Post-incident Activity
What is the purpose of a hypervisor?
It creates and runs virtual machines.
It monitors and logs network traffic for malicious packets.
It provides and monitors firewall services for cloud computing.
It provides and services a gateway between users and the internet.
What enables the network security team to keep track of the operating system version, security updates, and patches on end user’s devices?
Business continuity planning
Asset management
Incident management
Security policies and procedures
What should you create to prevent spoofing of the internal network?
A DNS record
A NAT rule
A record in the host file
An ACL
Which two private IPv4 addresses would be blocked on the internet to prevent security and performance issues? (Choose 2)
203.0.113.168
192.168.18.189
224.0.2.172
172.18.100.78
While conducting a risk evaluation at your company, you identify risks that are related to the web server located in the office. The risks include hardware and software failure as well as web service interruption caused by cyber attacks. You recommend purchasing insurance and hiring another organization to maintain the web server to help mitigate the risks. What type of risk management strategy is being applied?
Risk reduction
Risk avoidance
Risk acceptance
Risk transfer
Which CIA Triad term corresponds to the principle that "Data should be accessed and read by authorized users only"?
Integrity
Confidentiality
Availability
Authentication
Which CIA Triad term corresponds to the principle that "Data should never be altered or compromised"?
Confidentiality
Availability
Integrity
Encryption
Which CIA Triad term corresponds to the principle that "Legitimate requests should have access to data at all times"?
Availability
Confidentiality
Integrity
Authorization
The employees in the accounting department of a company receive an email about the latest federal regulations. The email contains a hyperlink to register for a webinar hosted by a government agency. As a security officer, you notice that the hyperlink points to an unknown party. Which type of cybersecurity threat should you investigate?
Spear phishing
Smishing
Ransomware
Vishing
Your home network seems to have slowed down considerably. You look at the home router GUI and notice that an unknown host is attached to the network. What should you do to prevent this specific host from attaching to the network again?
Implement MAC address filtering.
Create an IP access control list.
Change the network SSID.
Block the host IP address.
Which classification of security alert is the greatest threat to an organization because it represents undetected exploits?
False negative
False positive
True negative
True positive
You are working with the senior administration team to identify potential risks. Which phase of risk management are you in?
Choosing risk strategies
Measuring residual risk
Mitigating risks
Determining a risk profile
A corporation hires a group of experienced cyber criminals to create a prolonged and in-depth presence on the network of a competitor. This presence will allow the corporation to steal or sabotage. Which type of attack does this scenario describe?
Ransomware
Man-in-the-middle
APT
DDoS
You need to allow employees to access your company’s secure network from their homes. Which type of security should you implement?
SNMP
VPN
BYOD
IDS
Which data type is protected through hard disk encryption?
Data in process
Data at rest
Data in transit
Data in use
You need to transfer configuration files to a router across an unsecured network. Which protocol should you use to encrypt the files in transit?
TFTP
HTTP
SSH
Telnet
You are monitoring the syslog server and observe that the DNS server is sending messages with a Warning severity. What do these messages indicate about the operation of the DNS server?
The DNS server is unusable due to a severe malfunction and is shutting down
The server has a hardware error that does not require immediate attention
A condition exists that will cause errors in the future if the issue is not fixed
An error condition is occurring that must be addressed immediately
You are a security technician. You just completed a full scan of a Windows 10 PC. Where should you go to view the scan result?
Windows Task Manager
Windows System Logs
Windows Application Logs
Windows Security
Your organization's SIEM system alerts you that users are connecting to an unusual URL. You need to determine whether the URL is malicious and what type of threat it represents. What should you do?
Submit the URL to a threat intelligence portal for analysis
Ask users why they visited the website
Visit the URL to determine whether the website is legitimate
Block the URL by placing it on the network block list
Several employees complain that the company intranet site is no longer accepting their login information. You attempt to connect by using the URL and notice some misspellings on the site. When you connect by using the IP address, the site functions normally. What should you do?
Verify the accuracy of the entry for the site in the local DNS server
Take the company web portal offline immediately
Update the web server software to the latest version
Restore a backup copy of the authentication database
Which two actions should you take immediately to address unexplained computer crashes and unwanted pop-up messages without impacting data? (Choose 2)
Reinstall Windows on the affected workstations
Deploy a policy to install and automatically update antivirus and anti-malware software
Scan affected workstations and remove malware
Configure the network firewall to block malware from entering the internal network
A cybersecurity analyst is investigating an unknown executable file discovered on a Linux desktop computer. The analyst enters the following command in the terminal ls -l. What is the purpose of the command.
To display the content of a text file
To open a text editor
To display the file permission and ownership of the executable file
To navigate to the folder that is passed as an argument to the command
You need to filter the websites that are available to employees on the company network. Which type of device should you deploy?
IPS
Proxy server
IDS
Honeypot
A security analyst discovers that a hacker was able to gain root access to an enterprise Linux server. The hacker accessed the server as a guest, used a program to bypass the root password, and then killed essential processes as the root user. Which type of endpoint attack is this?
Buffer overflow
DDoS
Privilege escalation
Brute force
Which wireless encryption technology required AES to secure home wireless network?
WEP
WPA
WPA2
TKIP
Which three authentication factors are valid for use in a multifactor authentication scenario? (Choose 3)
Something you earn
Something you know
Something you are
Something you see
Something you have
True or False: A security analyst may use a disgruntled employee network credential to monitor behavior.
True
False
True or False: A security analyst may access employee data on a company server if authorized.
True
False
True or False: A security analyst may share sensitive data with unauthorized users.
True
False
What are two natural disasters that would cause a company to implement a disaster recovery plan? (Choose 2)
Hazardous material spills
Floods
Nuclear contamination
Volcanic eruptions
After an administrator installs an operating system update on a laptop, the laptop user can no longer print to their wireless printer. What should solve the issue?
Check for patches for wireless printers
Reinstall the same service pack
Install a new device driver for the wireless printer
Update the firmware on the laptop
Which activity is an example of active reconnaissance performed during a penetration test?
Using a browser to view the HTTP source code of company webpages
Gathering employee information from available web directories and social media
Performing an Nmap port scan on the LAN to determine types of connected devices and open ports
Searching the WHOIS database for the owner and technical contact information for a domain
You are reviewing company remote access procedures and notice that telnet is being used to connect to the corporate database server to check on inventory levels. Which two actions should you take immediately? (Choose 2)
Force users to implement secure telnet passwords.
Disable telnet access on the server.
Implement SSH access on the server.
Reconfigure the server to only accept HTTPS connection.
Which activity by an adversary is an example of an exploit that is attempting to gain credentials?
Installing a backdoor in order to enable two-way communication with the device.
Sending an email with a link to a fictitious web portal login page.
Obtaining a directory listing of files located on the web database server.
Executing a remote port scan of all of the enterprise-registered IP addresses.
Which two basic metrics should be taken into consideration when assigning a severity to a vulnerability during an assessment? (Choose 2)
The likelihood that an adversary can and will exploit the vulnerability
The impacts that an exploit of the vulnerability will have on the organization
The time involved in choosing replacement software to replace older systems
The age of the hardware running the software that contains the vulnerability
What are two disadvantages of public vulnerability databases? (Choose 2)
Threat actors can access the databases to learn how to vary their threats to avoid detection
Publicly available databases are incompatible with most security platforms
It can take a long time for reported vulnerabilities to be investigated and approved for addition to the databases
It is costly for intelligence analysts to document and submit newly discovered vulnerabilities
Which framework protects the personal information of members of the European Union?
HIPAA
GDPR
FERPA
PCI-DSS
Which framework is responsible for protecting the healthcare information of individuals?
FERPA
PCI-DSS
HIPAA
FISMA
Which framework protects the credit card information of individuals?
PCI-DSS
GDPR
HIPAA
FERPA
Which framework protects the educational records of individuals?
FISMA
FERPA
GDPR
HIPAA
Which framework protects information about individuals that is stored by federal agencies?
FERPA
PCI-DSS
FISMA
GDPR
Which command displays both the configured DNS server information and the IP address resolution for a URL?
Ping
Nslookup
Traceroute
Nmap
Customers of an online shopping store are complaining that they cannot visit the website. As an IT technician, you restart the website. After 30 minutes, the website crashes again. You suspect that the website has been experiencing which type of cybersecurity threat?
Spear phishing
Ransomware
Denial of service
Social engineering
You are a security analyst. You are reviewing output from the SIEM. You notice an alert concerning malicious files detected by the IDS. After reviewing the user, device, and posture information, you determine that it is a valid alert. What should you do next?
Escalate the situation immediately
Log the alert and watch for a second occurrence
Prepare notes to present at the weekly cybersecurity team meeting
Update the documentation to include the new alert information
In order to do online banking, you enter a strong password and then enter the 5-digit code sent to you on your smartphone. Which type of authentication does this situation describe?
VPN
Multifactor
AAA
RADIUS
What does hashing provide for the communication?
Data integrity
Data encryption
Data non-repudiation
Origin authentication
You work for a community health care organization that uses an electronic health record (EHR) system. You have implemented the physical and technical safeguards required by HIPAA. You need to prove that the EHR system is compliant with those safeguards. Which two approaches should you use to verify the system is compliant? (Choose 2).
Automatic log-off implementation
Penetration testing
Security awareness training
IT auditing
Move each cybersecurity tools from the list in the left to the correct location on the Vulnerability Process diagram on the right.
Discover: Nmap, Nessus Scanner
Prioritize: CVSS
Remediate: Window Auto Update, Patch Management Software
Discover: CVSS, Nmap
Prioritize: Patch Management Software
Remediate: Window Auto Update, Nessus Scanner
Discover: Window Auto Update, CVSS
Prioritize: Patch Management Software
Remediate: Nmap, Nessus Scanner
Clean and patch infection system
Treatment
Containment
Inoculation
Quarantine
Remove or block infected system from the network
Treatment
Containment
Inoculation
Quarantine
Patch uninfected systems to deprive the worm of more available targets
Treatment
Containment
Inoculation
Quarantine
Compartmentalize and segment the network to limit the spread of the worm to areas already infected
Treatment
Containment
Inoculation
Quarantine
People, property, or data
Asset
Threat
Risk
Vulnerability
An action that causes a negative impact
Asset
Threat
Risk
Vulnerability
The potential for loss, damage, or destruction
Asset
Threat
Risk
Vulnerability
A weakness that potentially exposes organizations to cyber attacks
Asset
Threat
Risk
Vulnerability
Discover unwanted event
Detective measures
Preventive measures
Corrective measures
Avert the occurrence of an event
Detective measures
Preventive measures
Corrective measures
Restore a system after an event
Detective measures
Preventive measures
Corrective measures
