WorksheetsCanvas 15
Total questions: 30
Worksheet time: 16mins
An executive who works for a large corporation goes on a business trip. During the trip, the executive's $2,500 laptop is stolen. Which of the following is most likely to be true regarding the value of the asset that was stolen? Select two.
There is a high probability the laptop itself is worth more than the data it contains.
The data could be restored from a backup, so the data is not a high-value asset in this context.
Even though the laptop costs $2,500, it may not necessarily be considered a high-value asset.
The operating system installed in the laptop is considered a high-value asset.
The data in the laptop is likely to be an asset with a greater value than the laptop itself.
A technician is documenting the entities considered to be IT assets. Which of the following should be included in the list? Select three.
a. Data center
b. IT personnel
c. Operating systems
d. USB drives
e. Marketing data
A SOC team is puzzled because they are monitoring periodic evidence of a breach but are unable to definitively identify the compromised device. Which of the following best describes what may be happening and/or how it could have been prevented? Select two.
Run quarterly vulnerability scans to identify rogue devices in the network.
A threat actor compromised a system that has not been accounted for.
A comprehensive CAM program could have prevented this situation.
Adopt gamification to use game-based scenarios that emulate this situation for security training.
A company replaced a router just before it became an EOL (end-of-life) product. Thus, it would no longer be supported by the manufacturer. Which of the following are costs that were likely NOT incurred during the lifecycle of the asset? Select two.
License renewals
Staff time
Transportation
Shipping and handling
Energy
Your company sells equipment to help secure internal networks. You are asked to submit a proposal electronically to a potential client. The proposal includes information on price, availability, service contract, and additional information. What process is being used to deliver the proposal?
E-proposal process
E-bidding process
Auction process
Standard bidding process
Elema owns a company that provides security services but also sells computers and security equipment such as intrusion detection system, intrusion prevention system, and firewalls. In terms of assets, how is the computer she uses in her office different from the two spare computers they keep in the stockroom for internal use and the computers they sell?Select two.
The computers they sell are considered a fixed asset.
The computer in Elema's office is considered a fixed asset.
The computers in the stockroom are considered intangible assets.
The computers in the stockroom are considered nonoperating assets.
The computers they sell are considered a transient asset.
Gulussa works in the property control department. He is responsible for tagging all incoming networking and security equipment with an internal serial number, as well as keeping a record of their location. What is this process called?
Inventory
Asset enumeration
Information security enumeration
Asset tracking
A local municipality is finally getting around to replacing all the hard disk drives (HDDs) in their data storage arrays connected to a storage area network with solid-state drives (SSDs). After transferring the data, destruction of the data on the HDDs needs to meet certain regulatory requirements. Which of the following methods of destroying data should they use?
Degauss the HDDs and then sanitize them.
Sanitize the HDDs and then degauss them.
Degauss the HDDs.
Sanitize the HDDs.
Format the HDDs.
A senior official of a company was fired for unethical practices and replaced. The new senior official required the immediate implementation of new business processes. Which of the following changes can potentially impact information security in a negative way? Select two.
Replacing passive serial numbers on all networking and security appliances with radio frequency ID stickers.
An approval process that adds up to two weeks before fixed assets can be purchased.
Adding a layer of managers to the organizational chart to ensure a greater degree of oversight.
Requiring everyone to enroll in security awareness training even if they don't use a computer.
A network engineer at a large facility gives a technician a configuration file and verbally asks them to update one of the switches. However, the technician accidentally updates the wrong switch. The problem is discovered because members of a particular department are calling the help desk, saying that the internet is down. How could this situation have been prevented?
Use a systematic change management process when modifying device configurations.
Do not allow technicians to escalate their privileges unless they are being supervised.
Use change management tools to automate device configuration modifications.
Have a business process in place that has a greater degree of oversight.
Which of the following statements are true regarding change management? Select two.
Change management comprises policies and procedures that fall under regulatory compliance.
Documentation is important in change management to roll back changes as needed.
Using Git for software version control is a type of tool used in change management.
Asset management and change management can be used interchangeably in some cases.
A company has four routers, 24 switches, 500 computers, and a few security appliances in their network infrastructure. Which of the following would be beneficial to help keep track of configuration changes to these assets?
Change management software
Spreadsheets
Version-control software
Flowcharts and Gantt charts
A company that delivers technical consulting services in the information security space loses a major account that provides 25% of their total revenue. What type of threat just became a reality for this company?
Operational
Strategic
Financial
Technical
An individual with supervisory experience returns to school and earns a degree in network security. The networking lab uses appliances from a specific vendor. Upon graduating, the individual gets a job as an IT manager but also performs a few technical tasks. When buying appliances, the individual insists on devices from the vendor the school uses. What kind of decision-making bias is the individual displaying?
Present
Anchoring
Confirmation
Fundamental
A company is in the middle of identifying and analyzing risks using the risk and control self-assessment (RSCA) methodology. A goal of the methodology is to minimize the effects of human factors when identifying risks. What are some of those factors? Select two.
Overreacting to risks associated with accidents
Underreacting to risks caused by a natural disaster
Overreacting to long-term risks
Overreacting to risks caused by intentional actions
An engineering firm has a series of servers with proprietary information. They want to perform a risk analysis based on the possibility of a data breach taking place as well as the impact of the breach should it be successful. What type of risk analysis should they perform?
Probabilistic
Historical
Qualitative
Quantitative
Larissa is including the mean time between failures reported by a manufacturer to help determine the likelihood of a certain risk taking place within a 365-day period. Which of the following is she trying to determine?
SLE
ALE
ARO
AV
IT assets of a large security training center near the coast are worth $2 million. If a severe hurricane hits, 25% of the equipment is likely to be damaged. What is the single-loss expectancy (SLE)?
Unable to determine without the ARO
Unable to determine without the ALE
$250,000
$500,000
A small insurance company has decided not to bid on a request to provide flood insurance for the IT assets of a company because the ALE exceeds $100,000. Which of the following statements coincides with the conclusion the insurance company has drawn?
There is a 5% chance a flood will damage 80% of the assets worth $2 million.
There is a 20% chance a flood will damage 20% of the assets worth $2 million.
There is a 10% chance a flood will damage 40% of the assets worth $2 million.
There is a 15% chance a flood will damage 35% of the assets worth $2 million.
Takeshi is creating a document to help represent some of the risks associated with information security. What type of document is Takeshi creating?
Risk tolerance heatmap
Risk threshold report
Key risk indicator matrix
Risk register
.Risk exposure document
Charlotte is filling out a color-coded tool to list the likelihood of risks and their potential impact. What tool is she using?
Risk matrix
Risk mitigation heatmap
Risk register matrix
Risk appetite heatmap
Valdis is on a team responsible for assessing the level of risk the company can accept for a given type of threat as well as the total risk the company can bear for a given risk posture. To succeed, which of the following best describes what they need to determine?Select two
Their risk tolerance
Their risk acceptance
Their risk appetite
Risk mitigation strategy
Possible risk exceptions
Even though the internal policy of a company states they must install all patches, the security team decides to bypass one of the patches because they believe the risk of applying it is greater than not applying it. Instead, they will wait for the next version of the patch. In the meantime, what strategy has the company adopted?Select two.
The company is avoiding the risk.
The company is granting an exception.
The company is mitigating the risk.
The company is accepting the risk.
A company bought and installed a newly released router. A month after installation the vendor issues a notice that a relatively difficult-to-exploit vulnerability has been found and will be patched in 30 days. Peter wants to do nothing and wait 30 days, Paul wants to revert to using the previous router, and Mary wants to buy cybersecurity insurance. Which one of the following statements is NOT true?
Peter wants to accept the risk.
Paul wants to avoid the risk.
Mary wants to transfer the risk.
Mary wants to mitigate the risk.
A company makes a series of automotive parts for multiple foreign and domestic automobile manufacturers. Their business practices require relationships with a wide variety of other organizations. Which of the following are most likely to pose third-party risks? Select three.
In-network doctors employees select through their benefits package
Material and product delivery channels
Subcontractors
Food trucks
Suppliers
You represent the IT department as a member of the team involved with establishing and maintaining partnerships with a variety of external entities. Which of the following most accurately represents potential third-party risks that need consideration? Select three.
Ensuring both parties back up each other's data
Privacy policy of the third party
Data ownership
Data storage
Initiating and terminating a partnership
Artemis visits a supplier to participate in a vendor monitoring effort to help reduce the risks associated with third parties. Which of the following are most likely to be included in the agenda? Select three.
Review the quarterly questionnaire about their supply–chain security protections.
Audit the results of their penetration testing.
Ensure the memorandum of understanding can be legally enforced.
Review evidence of internal audits.
Evaluate steps in the supply chain.
An independent contractor offers services providing practical and tangible security training to adults in various organizations. The training program includes a heavy hands-on component and makes provision for applying concepts based on questions presented by attendees. Which of the following statements are true regarding this mode of instruction?
The instructor uses an andragogical approach that will benefit kinesthetic learners.
The instructor uses an andragogical approach that will benefit auditory learners.
The instructor uses an andragogical approach that will benefit visual learners.
The instructor uses a pedagogical approach that will benefit kinesthetic learners.
The instructor uses a pedagogical approach that will benefit auditory learners.
A company wants to implement a security awareness training program that includes sending certain types of emails to help keep track of the extent to which employees are behaving like human firewalls. They also want to rotate the different types of messages based on job description and include links to online games in some of the messages. What type of training should they include?
Phishing simulations
Computer-based training
Rolebased awareness training
Gamification
Which of the following examples, whether it represents a threat, risk, or neither, could or should be included in a security awareness program at an organization? Select two.
Displaying warning signs at an airport to use your own charging block when charging your device.
Inserting a USB flash drive a student left behind in a classroom to help identify the owner.
Use computer-based training to deliver instruction because it is considered the best means of training.
Receiving a call from the president of the company urgently requesting a forgotten password.
Enforce a password that includes at least eight upper- and lowercase, special, and numeric characters.
