NEW
Font size
Worksheetsmodule 8 - cognate 3
Total questions: 77
Worksheet time: 39mins
Which core security principle is maintained through redundancy, DDoS protection, and disaster recovery?
Confidentiality
Integrity
Availability
Non-repudiation
Confidentiality, a core security principle, is primarily ensured using which two methods?
Cryptographic hashing and digital signatures
Encryption and access controls
Redundancy and DDoS protection
Threat modeling and risk assessment
Integrity is ensured via which of the following?
Multi-Factor Authentication (MFA)
Hardware Security Modules (HSM)
Cryptographic hashing and digital signatures
Cloud Access Security Brokers (CASB)
Network Security in the Digital Era is described as foundational to all network operations and digital transformation, and it extends beyond traditional networks to which areas?
Cloud, IoT, and mobile
Mainframe, on-premise, and legacy systems
WAN, LAN, and SAN
Zero Trust Network Access (ZTNA) and SASE
Which of the following is an example of a sophisticated threat mentioned in the document?
Ransomware
Cloud Workloads
TLS 1.3
Businesss impact analysis
Vulnerability weaknesses caused by human error, social engineering, or malicious insiders fall under which vulnerability category?
Technical
Human
Configuration
Physical
What is described as an emerging threat vector caused by improper cloud service settings?
Supply Chain Compromises
API Security Weaknesses
Cloud Misconfigurations
Advanced Persistent Threats (APTs)
What contemporary threat involves stealthy, continuous computer hacking processes?
Ransomware
Business Email Compromise (BEC)
Advanced Persistent Threats (APTs)
Microservices
An attack targeting third-party vendors and software dependencies is known as a(n):
Business Email Compromise (BEC)
Supply Chain Compromise
Technical Flaw
Nation-state attack
Malicious software that encrypts data and demands payment for restoration is defined as:
Advanced Persistent Threat (APT)
Ransomware
Cloud Misconfiguration
Social Engineering
Which security model requires verification for every access request, regardless of its source?
DevSecOps
Zero Trust Architecture
Cloud Security Posture Management (CSPM)
Secure Access Service Edge (SASE)
Integrating security practices into the DevOps pipeline for continuous security is the definition of:
Cloud Workloads
Zero Trust Architecture
DevSecOps
Security Orchestration & Response (SOAR)
What is an automated tool used for detecting and remediating cloud misconfigurations?
SIEM
Cloud Security Posture Management (CSPM)
Multi-Factor Authentication (MFA)
Hardware Security Module (HSM)
What cloud-native architecture combines network and security services?
ZTNA
CASB
Secure Access Service Edge (SASE)
EDR
What control within Identity & Access Management (IAM) is specifically used for controlling and monitoring privileged account access?
Multi-Factor Authentication (MFA)
Privileged Access Management (PAM)
TLS 1.3
Cloud Access Security Brokers (CASB)
What is the latest protocol mentioned for securing internet communications?
SSL 3.0
TLS 1.2
TLS 1.3
HTTPS
Physical devices that securely manage digital keys are known as:
Cloud Workloads
Hardware Security Modules (HSM)
Microservices
Endpoint Detection & Response (EDR)
Cloud Access Security Brokers (CASB) function as security policy enforcement points between which two parties?
Internal network and the firewall
Cloud users and providers
EDR and SIEM
ZTNA and SASE
Providing secure remote access based on user identity and context is the goal of:
Privileged Access Management (PAM)
Multi-Factor Authentication (MFA)
Zero Trust Network Access (ZTNA)
Hardware Security Module (HSM)
What tool continuously monitors and responds to threats on endpoints?
SIEM (Security Information & Event Management)
EDR (Endpoint Detection & Response)
SOAR (Security Orchestration & Response)
CASB (Cloud Access Security Brokers)
The continuous process of identifying and remediating security weaknesses is referred to as:
Business Impact Analysis
Quantum-Readiness
Vulnerability Management
Threat Prioritization
What systematic approach uses models like STRIDE and DREAD to identify and prioritize potential threats?
Risk Assessment
Business Impact Analysis
Threat Modeling
Security Orchestration & Response (SOAR)
What are independently deployable services that make up modern applications?
Cloud Workloads
Microservices
Critical Assets
Hardware Security Modules
Real-time analysis of security alerts is performed by which security operation tool?
XDR (Extended Detection & Response)
SOAR (Security Orchestration & Response)
SIEM (Security Information & Event Management)
EDR (Endpoint Detection & Response)
What platform provides cross-layer detection and response?
SIEM (Security Information & Event Management)
XDR (Extended Detection & Response)
SOAR (Security Orchestration & Response)
CASB (Cloud Access Security Brokers)
What tool is designed for automating security operations and response workflows?
EDR (Endpoint Detection & Response)
SIEM (Security Information & Event Management)
SOAR (Security Orchestration & Response)
CSPM (Cloud Security Posture Management)
The process of understanding the financial and operational consequences of security incidents is called:
Risk Assessment
Business Impact Analysis
Threat Prioritization
Threat Modeling
Focusing resources on the most likely and damaging attack scenarios is known as:
Risk Assessment
Business Impact Analysis
Threat Prioritization
Quantum-Readiness
What emerging requirement is defined as a formal record containing details and relationships of software components?
AI Security Governance
Software Bill of Materials (SBOM)
Quantum-Readiness
Critical Assets
Preparing for future quantum computing threats to current encryption is categorized as:
Vulnerability Management
AI Security Governance
Quantum-Readiness
DevSecOps
1. Statement 1: Network Security in the Digital Era is foundational to all digital transformation. Statement 2: Integrity is primarily ensured by redundancy and disaster recovery.
statement 1 is true, statement 2 is false
statement 1 is false, statement 2 is true
both statements are true
both statements are false
Statement 1: The CIA Triad stands for Confidentiality, Integrity, and Availability. Statement 2: Confidentiality is protected via encryption, access controls, and data classification.
A. statement 1 is true, statement 2 is false
B. statement 1 is false, statement 2 is true
C. both statements are true
D. both statements are false
Statement 1: Availability ensures systems and data are accessible when needed. Statement 2: Integrity prevents unauthorized modification of data using digital signatures.
statement 1 is true, statement 2 is false
statement 1 is false, statement 2 is true
both statements are true
both statements are false
Statement 1: Network security extends only to traditional on-premise networks. Statement 2: Sophisticated threats include Nation-state attacks and Ransomware.
statement 1 is true, statement 2 is false
statement 1 is false, statement 2 is true
both statements are true
both statements are false
Statement 1: Technical Flaws are security weaknesses caused by human error or malicious insiders. Statement 2: Supply Chain Compromises are attacks targeting third-party vendors and software dependencies.
statement 1 is true, statement 2 is false
statement 1 is false, statement 2 is true
both statements are true
both statements are false
Cloud Misconfigurations are security gaps caused by improper cloud service settings. API Security Weaknesses are a type of human vulnerability.
statement 1 is true, statement 2 is false
statement 1 is false, statement 2 is true
both statements are true
both statements are false
Ransomware is malicious software that demands payment for data restoration. Business Email Compromise (BEC) targets systems through exploiting technical flaws.
statement 1 is true, statement 2 is false
statement 1 is false, statement 2 is true
both statements are true
both statements are false
8. Statement 1: Advanced Persistent Threats (APTs) are defined as stealthy, continuous computer hacking processes. Statement 2: Critical Assets include Cloud Workloads and Microservices.
A. statement 1 is true, statement 2 is false
B. statement 1 is false, statement 2 is true
C. both statements are true
D. both statements are false
Zero Trust Architecture requires verification for every access request, regardless of source. Zero Trust Network Access (ZTNA) is a non-identity-centric approach to remote access security.
statement 1 is true, statement 2 is false
statement 1 is false, statement 2 is true
both statements are true
both statements are false
Statement 1: DevSecOps focuses on integrating security practices into the DevOps pipeline. Statement 2: Cloud Security Posture Management (CSPM) is used to manually detect cloud misconfigurations.
statement 1 is true, statement 2 is false
statement 1 is false, statement 2 is true
both statements are true
both statements are false
Statement 1: Threat Modeling is a systematic approach to identify and prioritize potential threats. Statement 2: SASE is a cloud-native architecture that combines network and security services.
statement 1 is true, statement 2 is false
statement 1 is false, statement 2 is true
both statements are true
both statements are false
Statement 1: Multi-Factor Authentication (MFA) requires only one verification method for access. Statement 2: Privileged Access Management (PAM) controls and monitors privileged account access.
statement 1 is true, statement 2 is false
statement 1 is false, statement 2 is true
both statements are true
both statements are false
TLS 1.3 is the latest protocol mentioned for securing internet communications. Hardware Security Modules (HSM) are physical devices that securely manage digital keys.
statement 1 is true, statement 2 is false
statement 1 is false, statement 2 is true
both statements are true
both statements are false
Cloud Access Security Brokers (CASB) enforce security policy between cloud users and providers. CASB is categorized under Endpoint Protection controls.
statement 1 is true, statement 2 is false
statement 1 is false, statement 2 is true
both statements are true
both statements are false
Statement 1: Endpoint Detection & Response (EDR) tools continuously monitor and respond to endpoint threats. Statement 2: EDR is considered a Network Security control.
statement 1 is true, statement 2 is false
statement 1 is false, statement 2 is true
both statements are true
both statements are false
Statement 1: ZTNA (Zero Trust Network Access) is an identity-centric approach to remote access security. Statement 2: SASE (Secure Access Service Edge) is a security model used for DevSecOps.
statement 1 is true, statement 2 is false
statement 1 is false, statement 2 is true
both statements are true
both statements are false
SIEM provides real-time analysis of security alerts. XDR is a tool used for automating security operations and response workflows.
statement 1 is true, statement 2 is false
statement 1 is false, statement 2 is true
both statements are true
both statements are false
Statement 1: XDR (Extended Detection & Response) is a cross-layer detection and response platform. Statement 2: SIEM is an acronym for Security Information & Event Management.
statement 1 is true, statement 2 is false
statement 1 is false, statement 2 is true
both statements are true
both statements are false
Statement 1: SOAR stands for Security Orchestration & Response. Statement 2: SOAR is used to manually respond to security incidents.
statement 1 is true, statement 2 is false
statement 1 is false, statement 2 is true
both statements are true
both statements are false
Risk Assessment is the process of identifying, analyzing, and evaluating security risks. Threat Prioritization focuses resources on the least likely attack scenarios.
statement 1 is true, statement 2 is false
statement 1 is false, statement 2 is true
both statements are true
both statements are false
Statement 1: Business Impact Analysis determines the technical cause of a security incident.
Statement 2: Risk Management in the Modern Context includes Business Impact Analysis.
statement 1 is true, statement 2 is false
statement 1 is false, statement 2 is true
both statements are true
both statements are false
Vulnerability Management is a continuous process of identifying and remediating security weaknesses. "MFA Everywhere" is listed as a Must-Implement Control.
statement 1 is true, statement 2 is false
statement 1 is false, statement 2 is true
both statements are true
both statements are false
AI Security Governance is an emerging requirement that manages risks associated with AI systems. Quantum-Readiness prepares for the threat of quantum computing to current encryption.
statement 1 is true, statement 2 is false
statement 1 is false, statement 2 is true
both statements are true
both statements are false
24. Statement 1: A Software Bill of Materials (SBOM) is an emerging requirement. Statement 2: An SBOM is a formal record of hardware components.
statement 1 is true, statement 2 is false
statement 1 is false, statement 2 is true
both statements are true
both statements are false
The STRIDE and DREAD methodologies are used in Threat Modeling. Microservices are defined as virtual machines running in cloud environments.
statement 1 is true, statement 2 is false
statement 1 is false, statement 2 is true
both statements are true
both statements are false
26. Statement 1: ZTNA is an evolution of traditional VPNs for remote access. Statement 2: CASB and CSPM are both classified under Cloud Security controls.
statement 1 is true, statement 2 is false
statement 1 is false, statement 2 is true
both statements are true
both statements are false
27. Statement 1: The purpose of cryptographic hashing is to ensure data confidentiality. Statement 2: Digital signatures are a method of ensuring data integrity.
statement 1 is true, statement 2 is false
statement 1 is false, statement 2 is true
both statements are true
both statements are false
28. Statement 1: Ransomware and Supply Chain Compromises are both specific examples of sophisticated threats. Statement 2: Protecting against sophisticated threats is a goal of modern network security.
statement 1 is true, statement 2 is false
statement 1 is false, statement 2 is true
both statements are true
both statements are false
29. Statement 1: Privileged Access Management (PAM) is a type of Security Monitoring tool. Statement 2: MFA Everywhere is an essential security practice.
statement 1 is true, statement 2 is false
statement 1 is false, statement 2 is true
both statements are true
both statements are false
SOAR helps automate security response workflows. Threat Prioritization is a process within Security Assessment & Planning.
statement 1 is true, statement 2 is false
statement 1 is false, statement 2 is true
both statements are true
both statements are false
What does the acronym CIA stand for in the context of Core Security Principles?
Cryptography, Intelligence, Authorization
Confidentiality, Integrity, Availability
Cloud, IoT, Authentication
Classification, Identity, Access
The systematic approach to identifying and prioritizing potential threats includes methodologies like STRIDE and DREAD. What process are they associated with?
Security Operations and Response (SOAR)
Digital Forensics and Evidence Acquisition (DFEA)
Threat Modeling
Business Impact Analysis (BIA)
What does the acronym ZTNA stand for?
Zero Tolerance Network Access
Zone Trust Network Administration
Zero Trust Network Access
Zonal Threat and Network Assessment
What does SASE represent in the context of network and security services?
Security Analysis and Service Engine
Simple Authentication and Secure Encryption
Secure Access Service Edge
Software Application Security Evaluation
DevSecOps describes the integration of security practices into the DevOps pipeline. What does the "Ops" in DevSecOps refer to?
Outsourced Processing Solutions
Operations
Optimized Protocols and Standards
Organizational Policy Structure
What does CSPM stand for, which uses automated tools for detecting and remediating cloud misconfigurations?
Critical Security Policy Management
Cloud System Performance Metrics
Compliance and Security Program Monitoring
Cloud Security Posture Management
APTs are defined as stealthy, continuous computer hacking processes. What does APT stand for?
Automated Phishing Threats
Active Protocol Tactics
Advanced Persistent Threats
Application Penetration Testing
What does MFA require for access, making it a critical control?
Managed Firewall Access
Multiple verification methods
Mandatory File Auditing
Minimum Firewall Allocation
PAM is used for controlling and monitoring privileged account access. What does PAM stand for?
Public Access Management
Perimeter Access Monitoring
Policy and Audit Mechanism
Privileged Access Management
In encryption and data protection, what does HSM stand for, referring to physical devices that manage digital keys securely?
Highly Secured Methodology
Hardware Security Modules
Host System Monitoring
Hybrid Security Model
SIEM provides real-time analysis of security alerts. What does SIEM stand for?
System Integration and Event Management
Security Information & Event Management
Secure Identity and Endpoint Management
Software Image and Execution Metrics
XDR is a cross-layer detection and response platform. What does XDR stand for?
External Data Replication
Extended Detection & Response
eXtended Data Retrieval
Executive Decision Reporting
What process does SOAR automate, using it to accelerate security response workflows?Software Operations and Analysis Reporting
Software Operations and Analysis Reporting
Security Orchestration & Response
Service Optimization and Risk assessment
System Ownership and Account Reconciliation
EDR tools continuously monitor and respond to endpoint threats. What does EDR stand for?
Encrypted Data Retrieval
Enterprise Device Registry
Endpoint Detection & Response
Event Data Reporting
CASBs act as security policy enforcement points between cloud users and providers. What does CASB stand for?
Cloud Application Security Benchmarks
Centralized Access Security Buffer
Cloud Access Security Brokers
Content and Asset Security Blueprint
What does SBOM stand for, which is a formal record containing details and relationships of software components?
Standard Business Operating Model
Security Baseline and Operation Metrics
System Build and Operation Management
Software Bill of Materials
What is the definition of BEC?
Basic Encryption Code
Business Email Compromise
Binary Exchange Communication
Breach Event Control
