WorksheetsSIEM and Incident Response Quiz
Total questions: 42
Worksheet time: 21mins
A security team chooses to implement a SIEM tool that they will install, operate, and maintain using their own physical infrastructure. What type of tool are they using?
Log-hosted
Hybrid
Self-hosted
Cloud-hosted
You are a security professional, and you want a SIEM tool that will require both on-site infrastructure and internet-based solutions. What type of tool do you choose?
Component-hosted
Self-hosted
Hybrid
Cloud-hosted
Fill in the blank: SIEM tools are used to search, analyze, and _____ an organization's log data to provide security information and alerts in real-time.
retain
modify
release
separate
A security analyst receives an alert about hundreds of login attempts from unusual geographic locations within the last few minutes. What can the analyst use to review a timeline of the login attempts, locations, and time of activity?
A playbook
An operating system
A SIEM tool dashboard
A network protocol analyzer (packet sniffer)
Which type of tool typically requires users to pay for usage?
Proprietary
Self-hosted
Open-source
Cloud native
Fill in the blank: A security team _____ their playbook frequently by learning from past security incidents, then refining policies and procedures.
summarizes
outlines
updates
shortens
Fill in the blank: Incident response playbooks are _____ used to help mitigate and manage security incidents from beginning to end.
inquiries
guides
exercises
examinations
An organization has successfully responded to a security incident. According to their established standards, the organization must share information about the incident to a specific government agency. What phase of an incident response playbook does this scenario describe?
Containment
Coordination
Detection and analysis
Preparation
Why is the containment phase of an incident response playbook a high priority for organizations?
It demonstrates how to communicate about the breach to leadership.
It enables a business to determine whether a breach has occurred.
It outlines roles and responsibilities of all stakeholders.
It helps prevent ongoing risks to critical assets and data.
Fill in the blank: During the post-incident activity phase, security teams may conduct a full-scale analysis to determine the _____ of an incident and use what they learn to improve the company’s overall security posture.
end point
structure
target
root cause
A security analyst wants to set the foundation for successful incident response. They outline roles and responsibilities of each security team member. What phase of an incident response playbook does this scenario describe?
Preparation
Detection and analysis
Post-incident activity
Containment
What is the term for a group of connected devices?
Hub
Protocol
Cloud
Network
A _____ broadcasts information to every device on the network.
modem
hub
switch
router
What is the purpose of the protocol number of a data packet?
To contain the IP and MAC addresses
To identify the message to be transmitted to the receiving device
To signal to the receiving device that the packet is finished
To tell the receiving device what to do with the information in the packet
Fill in the blank: _____ refers to the practice of using remote servers, applications, and network services that are hosted on the internet, instead of in a physical location owned by a company.
Hybrid cloud environment
Software defined networks (SDNs)
Local area network (LAN)
Which port is used for secure internet communication?
20
443
25
40
Fill in the blank: The ___ layer is used to determine how data packets will interact with receiving devices, including file transfers and email services.
Layer 1, network access
Layer 2, internet
Layer 3, transport
Layer 4, application
A security analyst runs a command to discover a local IP address. The analyst receives the following result: 169.254.255.249. What type of address is this?
IPv4
Ethernet
IPv6
MAC
Fill in the blank: fe80::ab12:cd34:ef56:0023:2345 is an example of an accurate ___ address.
IPv4
IPv6
MAC
Ethernet
What network protocol helps data get to the right place by determining the MAC address of the next router or device on its path?
Transmission Control Protocol (TCP)
Hypertext Transfer Protocol Secure (HTTPS)
Address Resolution Protocol (ARP)
Secure Sockets Layer/Transport Layer Security (SSL/TLS)
Which type of firewall analyzes network traffic for suspicious characteristics and behavior and stops them from entering the network?
Stateful
Next-generation firewall (NGFW)
Stateless
Cloud-based
Which firewall offers the most security features?
Stateless firewall
Next generation firewall (NGFW)
Documented firewall
Stateful firewall
What network security service masks a device’s virtual location to keep data private while using a public network?
Network segmenter
Cloud service provider (CSP)
Virtual private network (VPN)
Domain name system (DNS)
What network security service masks a device’s virtual location to keep data private while using a public network?
Network segmenter
Virtual private network (VPN)
Cloud service provider (CSP)
Domain name system (DNS)
What does a VPN service use to transfer encrypted data between a device and the VPN server?
encapsulation
transmission control
network segmentation
packet sniffing
What network zone contains the internet and other services that are outside of an organization’s control?
Restricted
Controlled
Demilitarized
Uncontrolled
What network zone acts as a network perimeter to the internal network by isolating servers that are exposed to the internet?
Demilitarized zone
Virtual private network
Restricted zone
Uncontrolled zone
Fill in the blank: A _____ fulfills the requests of its clients by forwarding them to other servers
virtual private network (VPN)
router
proxy server
firewall
What happens during a Denial of Service (DoS) attack?
The data packets containing valuable information are stolen as they travel across the network.
The attacker successfully impersonates an authorized user and gains access to the network.
The network is infected with malware.
The target crashes and normal business operations cannot continue.
A security team discovers that an attacker has taken advantage of the handshake process that is used to establish a TCP connection between a device and their server. Which DoS attack does this scenario describe?
Ping of Death
On-path attack
ICMP flood
SYN flood attack
Fill in the blank: The maximum size of a correctly formatted IPv4 ICMP packet is _____, as opposed to the oversized packet that is sent during a Ping of Death attack.
64KB
15Gb
32KB
64TB
As a security professional, you implement safeguards against attackers changing the source IP of a data packet in order to communicate over your company’s network. What type of network attack are you trying to avoid?
Ping of Death
IP spoofing
Active packet sniffing
Passive packet sniffing
Fill in the blank: To reduce the chances of an IP spoofing attack, a security analyst can configure a _____ to reject all incoming traffic with the same source IP addresses as those owned by the organization.
demilitarized zone
VPN
firewall
HTTPS domain address
In which attack would malicious actors gain access to a network, put themselves between a web browser and a web server, then sniff the packet to learn the devices’ IP and MAC addresses?
Packet flooding attack
Malware attack
Smurf attack
On-path attack
Fill in the blank: The _____ network attack occurs when a malicious actor takes a network transmission that was sent by an authorized user and repeats it at a later time to impersonate that user.
SYN flood
smurf
on-path
replay
Which attack is a combination of a DDoS and an IP spoofing attack, during which the malicious actor overwhelms a target computer?
Smurf attack
On-path attack
Ping of Death
Replay attack
Fill in the blank: ____ is the process of strengthening a system to reduce its vulnerability and attack surface.
Security hardening
Network hardening
Port filtering
SIEM
What is the relationship between security hardening and an attack surface?
Security hardening permanently eliminates the attack surface.
Security hardening diminishes the attack surface.
Security hardening expands the attack surface.
Security hardening increases the attack surface.
Fill in the blank: Installing security cameras is an example of a _____ security hardening practice.
network-focused
physical
software-based
virtual
An organization’s in-house security team has been authorized to simulate an attack on the organization’s website. The objective is to identify any vulnerabilities that are present. What does this scenario describe?
The Ping of Death
Penetration testing
A Distributed Denial of Service (DDoS) attack
Packet sniffing
A security analyst reviews documentation about a firewall rule that includes a list of allowed and disallowed network ports. They compare it to the current firewall to ensure no changes have been made. What does this scenario describe?
Checking baseline configuration
Upgrading the interface between computer hardware and the user
Responsibly managing applications
Verifying user identity when accessing an OS
Which OS hardening practice requires users to verify their identity in two or more ways to access a system or network?
Multi-factor authentication (MFA)
SIEM
Port filtering
Patch updates
