Font size
WorksheetsCybersecurity Knowledge Assessment
Total questions: 30
Worksheet time: 15mins
A SOC analyst observes a workstation generating outbound HTTPS traffic to an unfamiliar domain every 300 seconds. The domain resolves to different IP addresses over time, and no user activity aligns with the traffic. What does this behavior MOST likely indicate?
Load-balanced web traffic
Beaconing to a C2 infrastructure
Legitimate cloud API communication
Misconfigured DNS forwarding
An organization is migrating to a zero trust architecture. Which implementation BEST aligns with zero trust principles?
Allowing VPN access to all internal resources
Enforcing MFA only for remote users
Continuous authentication and authorization per session
Deploying perimeter firewalls with IDS
An analyst is validating whether a suspicious email was spoofed. Which TWO controls MOST directly verify sender authenticity?
SPF
DKIM
TLS
HTTPS
Which tool provides the BEST method to safely observe runtime behavior of a suspicious executable?
VirusTotal
Wireshark
Cuckoo Sandbox
WHOIS
Which host-based indicator MOST strongly suggests malware persistence?
High memory utilization
Abnormal DNS queries
Unauthorized scheduled tasks
Increased outbound traffic
Which threat actor is MOST likely to use long-term stealth, custom tooling, and supply-chain compromise?
Script kiddie
Hacktivist
Organized crime
Nation-state APT
Which source represents closed-source threat intelligence?
CERT advisories
Dark web forums
Paid intelligence feeds
Public GitHub repositories
Which scripting language is MOST effective for automating Windows security response actions?
Python
Bash
PowerShell
Ruby
Integrating SIEM, EDR, and threat-intel platforms into a unified dashboard BEST demonstrates:
Defense in depth
Single pane of glass
Network segmentation
Zero trust
Which SOAR capability MOST reduces analyst fatigue during high alert volumes?
Alert dashboards
Threat visualization
Automated response playbooks
Log normalization
Which scanning method provides the MOST comprehensive vulnerability results?
External, non-credentialed
Passive network scanning
Credentialed internal scanning
Web application fuzzing
A security team wants vulnerability insight without impacting production systems. What is the BEST approach?
Active scanning during off-hours
Passive vulnerability scanning
Aggressive fuzz testing
Reverse engineering binaries
A vulnerability has a low attack complexity and requires no privileges. What does this MOST strongly indicate?
High exploitability
Low severity
Internal-only exposure
False positive
Which vulnerability allows attackers to execute database commands via unsanitized input?
Reflected XSS
CSRF
SQL injection
Directory traversal
A Web Application Firewall (WAF) is classified as which control type?
Managerial
Operational
Detective
Technical
Which risk response strategy involves acknowledging risk without remediation?
Mitigate
Transfer
Avoid
Accept
Which tool BEST assesses misconfigurations in AWS environments?
Nessus
Metasploit
Prowler
Nmap
Which practice focuses on identifying and reducing externally exposed assets?
Threat modeling
Attack surface management
Defense in depth
Zero trust
Which secure coding practice MOST effectively prevents SQL injection?
Output encoding
Input length validation
Parameterized queries
Session tokens
Which vulnerability tricks a server into making unauthorized internal requests?
XXE
CSRF
SSRF
RFI
Which framework maps adversary tactics, techniques, and procedures?
Cyber Kill Chain
MITRE ATT&CK
Diamond Model
OSSTMM
What ensures evidence integrity during incident investigations?
Encryption
Chain of custody
Data masking
Obfuscation
Isolating infected systems occurs during which IR phase?
Preparation
Detection
Containment
Recovery
Which post-incident activity determines WHY the incident occurred?
Threat hunting
Root cause analysis
Vulnerability scanning
Asset discovery
Which activity MOST improves organizational readiness for future incidents?
Penetration testing
Tabletop exercises
Threat intelligence sharing
Vulnerability scanning
Which metric measures how quickly incidents are identified?
MTTR
MTTD
SLA
KPI
Which report section is MOST appropriate for executive leadership?
Packet captures
Raw logs
Executive summary
Hash values
Which factor MOST commonly delays remediation efforts?
CVSS calculation
Asset discovery
Legacy systems
Automation
Who MUST be involved when an incident may require public disclosure?
SOC analysts
Legal and public relations
Developers
Network engineers
Which metric BEST helps assess SOC workload trends?
Alert volume
Encryption strength
Patch cadence
Throughput
