Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

SIEM and Incident Response Quiz

Total questions: 42

Worksheet time: 21mins

Name
Class
Date
1.

A security team chooses to implement a SIEM tool that they will install, operate, and maintain using their own physical infrastructure. What type of tool are they using?

a)

Log-hosted

b)

Hybrid

c)

Self-hosted

d)

Cloud-hosted

2.

You are a security professional, and you want a SIEM tool that will require both on-site infrastructure and internet-based solutions. What type of tool do you choose?

a)

Component-hosted

b)

Self-hosted

c)

Hybrid

d)

Cloud-hosted

3.

Fill in the blank: SIEM tools are used to search, analyze, and _____ an organization's log data to provide security information and alerts in real-time.

a)

retain

b)

modify

c)

release

d)

separate

4.

A security analyst receives an alert about hundreds of login attempts from unusual geographic locations within the last few minutes. What can the analyst use to review a timeline of the login attempts, locations, and time of activity?

a)

A playbook

b)

An operating system

c)

A SIEM tool dashboard

d)

A network protocol analyzer (packet sniffer)

5.

Which type of tool typically requires users to pay for usage?

a)

Proprietary

b)

Self-hosted

c)

Open-source

d)

Cloud native

6.

Fill in the blank: A security team _____ their playbook frequently by learning from past security incidents, then refining policies and procedures.

a)

summarizes

b)

outlines

c)

updates

d)

shortens

7.

Fill in the blank: Incident response playbooks are _____ used to help mitigate and manage security incidents from beginning to end.

a)

inquiries

b)

guides

c)

exercises

d)

examinations

8.

An organization has successfully responded to a security incident. According to their established standards, the organization must share information about the incident to a specific government agency. What phase of an incident response playbook does this scenario describe?

a)

Containment

b)

Coordination

c)

Detection and analysis

d)

Preparation

9.

Why is the containment phase of an incident response playbook a high priority for organizations?

a)

It demonstrates how to communicate about the breach to leadership.

b)

It enables a business to determine whether a breach has occurred.

c)

It outlines roles and responsibilities of all stakeholders.

d)

It helps prevent ongoing risks to critical assets and data.

10.

Fill in the blank: During the post-incident activity phase, security teams may conduct a full-scale analysis to determine the _____ of an incident and use what they learn to improve the company’s overall security posture.

a)

end point

b)

structure

c)

target

d)

root cause

11.

A security analyst wants to set the foundation for successful incident response. They outline roles and responsibilities of each security team member. What phase of an incident response playbook does this scenario describe?

a)

Preparation

b)

Detection and analysis

c)

Post-incident activity

d)

Containment

12.

What is the term for a group of connected devices?

a)

Hub

b)

Protocol

c)

Cloud

d)

Network

13.

A _____ broadcasts information to every device on the network.

a)

modem

b)

hub

c)

switch

d)

router

14.

What is the purpose of the protocol number of a data packet?

a)

To contain the IP and MAC addresses

b)

To identify the message to be transmitted to the receiving device

c)

To signal to the receiving device that the packet is finished

d)

To tell the receiving device what to do with the information in the packet

15.

Fill in the blank: _____ refers to the practice of using remote servers, applications, and network services that are hosted on the internet, instead of in a physical location owned by a company.

a)
Cloud computing
b)

Hybrid cloud environment

c)

Software defined networks (SDNs)

d)

Local area network (LAN)

16.

Which port is used for secure internet communication?

a)

20

b)

443

c)

25

d)

40

17.

Fill in the blank: The ___ layer is used to determine how data packets will interact with receiving devices, including file transfers and email services.

a)

Layer 1, network access

b)

Layer 2, internet

c)

Layer 3, transport

d)

Layer 4, application

18.

A security analyst runs a command to discover a local IP address. The analyst receives the following result: 169.254.255.249. What type of address is this?

a)

IPv4

b)

Ethernet

c)

IPv6

d)

MAC

19.

Fill in the blank: fe80::ab12:cd34:ef56:0023:2345 is an example of an accurate ___ address.

a)

IPv4

b)

IPv6

c)

MAC

d)

Ethernet

20.

What network protocol helps data get to the right place by determining the MAC address of the next router or device on its path?

a)

Transmission Control Protocol (TCP)

b)

Hypertext Transfer Protocol Secure (HTTPS)

c)

Address Resolution Protocol (ARP)

d)

Secure Sockets Layer/Transport Layer Security (SSL/TLS)

21.

Which type of firewall analyzes network traffic for suspicious characteristics and behavior and stops them from entering the network?

a)

Stateful

b)

Next-generation firewall (NGFW)

c)

Stateless

d)

Cloud-based

22.

Which firewall offers the most security features?

a)

Stateless firewall

b)

Next generation firewall (NGFW)

c)

Documented firewall

d)

Stateful firewall

23.

What network security service masks a device’s virtual location to keep data private while using a public network?

a)

Network segmenter

b)

Cloud service provider (CSP)

c)

Virtual private network (VPN)

d)

Domain name system (DNS)

24.

What network security service masks a device’s virtual location to keep data private while using a public network?

a)

Network segmenter

b)

Virtual private network (VPN)

c)

Cloud service provider (CSP)

d)

Domain name system (DNS)

25.

What does a VPN service use to transfer encrypted data between a device and the VPN server?

a)

encapsulation

b)

transmission control

c)

network segmentation

d)

packet sniffing

26.

What network zone contains the internet and other services that are outside of an organization’s control?

a)

Restricted

b)

Controlled

c)

Demilitarized

d)

Uncontrolled

27.

What network zone acts as a network perimeter to the internal network by isolating servers that are exposed to the internet?

a)

Demilitarized zone

b)

Virtual private network

c)

Restricted zone

d)

Uncontrolled zone

28.

Fill in the blank: A _____ fulfills the requests of its clients by forwarding them to other servers

a)

virtual private network (VPN)

b)

router

c)

proxy server

d)

firewall

29.

What happens during a Denial of Service (DoS) attack?

a)

The data packets containing valuable information are stolen as they travel across the network.

b)

The attacker successfully impersonates an authorized user and gains access to the network.

c)

The network is infected with malware.

d)

The target crashes and normal business operations cannot continue.

30.

A security team discovers that an attacker has taken advantage of the handshake process that is used to establish a TCP connection between a device and their server. Which DoS attack does this scenario describe?

a)

Ping of Death

b)

On-path attack

c)

ICMP flood

d)

SYN flood attack

31.

Fill in the blank: The maximum size of a correctly formatted IPv4 ICMP packet is _____, as opposed to the oversized packet that is sent during a Ping of Death attack.

a)

64KB

b)

15Gb

c)

32KB

d)

64TB

32.

As a security professional, you implement safeguards against attackers changing the source IP of a data packet in order to communicate over your company’s network. What type of network attack are you trying to avoid?

a)

Ping of Death

b)

IP spoofing

c)

Active packet sniffing

d)

Passive packet sniffing

33.

Fill in the blank: To reduce the chances of an IP spoofing attack, a security analyst can configure a _____ to reject all incoming traffic with the same source IP addresses as those owned by the organization.

a)

demilitarized zone

b)

VPN

c)

firewall

d)

HTTPS domain address

34.

In which attack would malicious actors gain access to a network, put themselves between a web browser and a web server, then sniff the packet to learn the devices’ IP and MAC addresses?

a)

Packet flooding attack

b)

Malware attack

c)

Smurf attack

d)

On-path attack

35.

Fill in the blank: The _____ network attack occurs when a malicious actor takes a network transmission that was sent by an authorized user and repeats it at a later time to impersonate that user.

a)

SYN flood

b)

smurf

c)

on-path

d)

replay

36.

Which attack is a combination of a DDoS and an IP spoofing attack, during which the malicious actor overwhelms a target computer?

a)

Smurf attack

b)

On-path attack

c)

Ping of Death

d)

Replay attack

37.

Fill in the blank: ____ is the process of strengthening a system to reduce its vulnerability and attack surface.

a)

Security hardening

b)

Network hardening

c)

Port filtering

d)

SIEM

38.

What is the relationship between security hardening and an attack surface?

a)

Security hardening permanently eliminates the attack surface.

b)

Security hardening diminishes the attack surface.

c)

Security hardening expands the attack surface.

d)

Security hardening increases the attack surface.

39.

Fill in the blank: Installing security cameras is an example of a _____ security hardening practice.

a)

network-focused

b)

physical

c)

software-based

d)

virtual

40.

An organization’s in-house security team has been authorized to simulate an attack on the organization’s website. The objective is to identify any vulnerabilities that are present. What does this scenario describe?

a)

The Ping of Death

b)

Penetration testing

c)

A Distributed Denial of Service (DDoS) attack

d)

Packet sniffing

41.

A security analyst reviews documentation about a firewall rule that includes a list of allowed and disallowed network ports. They compare it to the current firewall to ensure no changes have been made. What does this scenario describe?

a)

Checking baseline configuration

b)

Upgrading the interface between computer hardware and the user

c)

Responsibly managing applications

d)

Verifying user identity when accessing an OS

42.

Which OS hardening practice requires users to verify their identity in two or more ways to access a system or network?

a)

Multi-factor authentication (MFA)

b)

SIEM

c)

Port filtering

d)

Patch updates