Font size
WorksheetsCCST 100-160 Cybersecurity Practice Questions #2
Total questions: 25
Worksheet time: 18mins
Match each worm mitigation step from the list below to the correct description. Note: You will receive partial credit for each correct answer:
Containment
Innoculation
Treatment
Quarantine
Clean and patch infected systems
Treatment
Remove or block infected systems from the network
Quarantine
Patch uninfected systems to deprive the worm of more available targets
Innoculation
Compartmentalize and segment the network to limit the spread of the worm to areas already infected
Containment
A restaurant installs a second wireless router that only employees can use. Which statement describes how to securely configure the new router?
Configure the new router to filter IP addresses..
Configure the SSID with broadcast disabled
Configure a higher signal strength to allow coverage in the parking lot.
Configure the SSID with the same SSID used by the customer router
You need to transfer configuration files to a router across an unsecured network. Which protocol should you use to encrypt the files in transit?
Telnet
HTTP
TFTP
SSH
You need to diagram an intrusion event by using the Diamond Model. Select each event detail from the list below to the correct location in the diagram:
Customer and product databases
Ransomeware group
Phising Email, Malware
Email Server, Domain Name
Adversary
Ransomeware Group
Capability
Phising Email, Malware
Infrastructure
Email Server, Domain Name
Victum
Customer and product databases
Your company is creating a BYOD policy to allow employees to join their personal smartphones to the company network. Which three requirements are commonly included in a BYOD policy? (Choose 3.)
Deletion of all personal data from the phone
Synchronization of phone lock screen password with network access password F. Installation of secure apps only
Encryption of stored confidential corporate data
Configuration of a strong password
Upgrade of data plan to maximum available
You notice that a new CVE has been shared to an email group that you belong to. What should you do first with the CVE
Look up details of the vulnerability to determine whether it applies to your network. .
Research measures to prevent the CVE from attacking the network
Record the CVE as part of the disaster recovery plan.
Add the CVE to the firewall rules for your organization.
Which encryption type is commonly used to secure WiFi networks?
Data Encryption Standard (DES)
Triple Data Encryption Algorithm (Triple DES)
Advanced Encryption Algorithm (AES)
RSA (Rivest–Shamir–Adleman)
You need to manage security risks at your company. In which order should you complete the actions? Move all the actions to the answer area and place them in the correct order
Action Order 1
Identify the Risks
Action Order 2
Prioritize the Risks
Action Order 3
Implement a Response
Action Order 4
Monitor Results
How does sandboxing help with the analysis of malware?
It defines the suspicious or malicious applications that should be blocked. .
It specifies the applications that are authorized for use on the network
It allows suspicious applications to run in a safe and isolated testing environment.
It restricts traffic from passing from one network to another.
Which network security technology passively monitors network traffic and compares the captured packet stream with known malicious signatures?
IDS
IPS
Proxy
Server
Honeypot
Your supervisor tells you that you will participate in a CVSS assessment. What will you be doing?
Performing penetration tests on internal network devices and end systems
Analyzing host logs to identify abnormal activities
Interviewing users to determine their level of cybersecurity awareness
Evaluating end system security and scoring software vulnerabilities
The company web server collects information through a form. The form is accessed by using port 80. The form content is transferred to an encrypted database for storage. You are investigating a complaint that the form content has been compromised. What is the cause of the security breach?
The database was compromised.
The data was transferred to the database using a nonsecure protocol.
The website was accessed using HTTP, which is an unencrypted protocol.
The web browser used to access the site was not updated to the latest version.
You work for a hospital that stores electronic protected health information (ePHI) in an online portal. Authorized employees can use their mobile devices to access patient ePHI. You need to ensure that employees’ mobile devices comply with HIPAA regulations. Which safeguard should you develop and implement?
An ownership policy for employees’ mobile devices
A contingency plan
A policy that requires multi-factor authentication to use the mobile device
A policy to govern how ePHI is removed from mobile devices
You need to design your company’s password policy to adhere to the National Institute of Standards and Technology (NIST) guidelines for user password security. What is the minimum password length that you should require to be consistent with the NIST guidelines?
4 characters
8 characters
16 characters
No minimum length
Select each framework from the list below to the correct purpose:
FERPA
FISMA
GDPR
HIPAA
PCI-DSS
Protect the personal information of members of the European Union
GDPR
Protects the healthcare information of individuals
HIPAA
Protects the credit card information of individuals
PCI-DSS
Protects the educational records of individuals
FERPA
Protects information about individuals that is stored by federal agencies.
FISMA
You need a software solution that performs the following tasks:
Compiles network data
Logs information from many sources
Provides orchestration in the form of case management
Automates incident response workflows
What product should you use?
SIEM
SOAR
NextGen IPS
Snort
Select each scenario from the list below to the correct type of attacker:
Tries to profit from personal data gained by spamming companies or individuals
Cyber Criminal
Works in conjunction with government to promote its agenda
State-Sponsored Attacker
Works as a company contractor who installs malware on a server
Insider Threat
Interfers in government election to promote a self-defined sense of justice
Hactivist
You are collecting data after a suspected intrusion on the local LAN. You need to capture incoming IP packets to a file for an investigator to analyze. Which two tools should you use? (Choose 2.)
Wireshark
tcpdump
Nmap
netstat
You are reviewing the Application log on a Windows computer. You see an event with an error-level message as shown. What can you determine about the application that generated the event message?
The application is currently running much slower than expected.
The application experienced a significant problem that caused it to fail.
The application recovered from an event without loss of functionality.
The application loaded and ran successfully without issues.
Which security measure can prevent unauthorized devices from automatically connecting to a corporate network through unused switch ports?
Port security
VLAN trunking
NAT
VPN
An administrator wants to ensure that any files downloaded from the internet are automatically scanned for malicious code before execution. Which security control should be implemented?
Host-based firewall
Anti-malware with real-time protection
VPN client
Patch management system
Which step should be performed immediately after identifying a critical vulnerability affecting internet-facing systems?
Which step should be performed immediately after identifying a critical vulnerability affecting internet-facing systems?
Apply the vendor patch or mitigation.
Schedule a quarterly penetration test.
Change the default administrator passwords.
A SOC analyst notices repeated failed login attempts from a foreign IP address followed by a successful login to a privileged account. What is the most appropriate next step?
Reset the affected user’s password and investigate the scope of compromise.
Block all foreign IP addresses from accessing the network.
Run a full vulnerability scan of the corporate network.
Ignore the event unless it happens again.
Which wireless security protocol provides the strongest protection for a home or small business network?
WEP
WPA
WPA2 with AES
WPA3
During an incident response, the security team needs to isolate a compromised server from the rest of the network but still allow forensic analysis. Which action should they take?
Power off the server immediately.
Disconnect the server from the network and connect it to an isolated forensic network.
Delete suspicious files from the server.
Reset all user passwords on the server.
