Font size
WorksheetsThe Cybersecurity Intelligence Framework Overview
Total questions: 57
Worksheet time: 40mins
Which domain focuses on understanding adversaries and their potential impact?
Incident Response and Forensics
Protective Architecture and Controls
Vulnerability and Risk Management
Threat Intelligence and Impact Analysis
Which domains in the diagram primarily focus on strengthening defenses rather than studying attackers? Select all that apply.
Vulnerability and Risk Management
Protective Architecture and Controls
Threat Intelligence and Impact Analysis
Incident Response and Forensics
What is the main purpose of Incident Response and Forensics?
Understanding how to fight back and learn
Understanding your own weaknesses
Understanding your defenses
Understanding the enemy and the stakes
Which scenario best describes a phishing attack in an enterprise environment?
An email spoofing a bank requests a password reset
A worm auto-replicates across internal subnets
A DoS flood makes the website unavailable
An insider copies files to a personal USB drive
What distinguishes ransomware from general malware?
Encrypts victim data and demands payment
Self-replicates without user interaction
Only disables service through traffic floods
Primarily exfiltrates credentials and tokens
Which attack primarily aims to overwhelm a service and block legitimate access?
Phishing lures tricking users into disclosure
Ransomware encrypting operational datasets
Insider misuse of authorized permissions
Denial of Service flooding traffic volumes
Select ALL incidents that involve unauthorised access to sensitive information.
Insider misuse to read HR files
DoS traffic exhaustion of endpoints
Phishing capture of login passwords
Data breach of financial records
Which business impact best matches a prolonged outage of an online store due to a DoS attack?
Operational loss through service disruption
Reputation loss from customer opinions
Intellectual property loss of designs
Financial loss from regulatory fines
A company pays compensation after customer data theft. Which loss category is the most direct?
Reputation loss from churn risk
Operational loss reducing capacity
Financial loss from payout costs
Intellectual property loss exposure
Which examples best illustrate reputation loss for an organisation?
Manufacturing output decline from downtime
Legal fees paid after compliance audit
Customer churn after repeated outages
Lowered trust over stolen personal data
Competitors gain advantage through stolen trade secrets. What type of loss is this?
Reputation decline without theft
Financial expense increase only
Operational capability reduction
Intellectual property loss impact
What is the core purpose of a Threat Intelligence Report?
Deliver penetration test tool binaries
Archive last year’s incident tickets only
Offer static compliance policy templates
Provide timely updates on changing threats
Which items are commonly included in a Threat Intelligence Report? Select ALL that apply.
Analysis of recently breached vulnerabilities
Updates on new malware and phishing tactics
Inventory of internal printers by location
Information on threat actors and their methods
Why is relying on last month’s threats insufficient for defenders?
Threats evolve, requiring current awareness
Vendors instantly patch every vulnerability
Old threats are legally prohibited to study
Networks auto-block all past attack types
Which strategic question can a Threat Intelligence Report help decision-makers answer?
Where should defensive efforts be focused next quarter?
How is printer toner consumption calculated?
Which employee has perfect attendance?
What color theme suits the website UI?
Which statement best defines a system vulnerability in IT?
Any hardware failure without security impact
A weakness, error, or flaw that can be exploited
A rare issue with no practical risk
A misconfiguration that cannot be exploited
Which items are part of the internal attack surface in an organisation?
Employee usage processes and credential handling
Cloud accounts and insecure IoT devices
Printer paper quality and office layouts
Network configurations and external storage devices
What is a common organisational vulnerability?
Mandatory multi-factor authentication everywhere
Poorly managed file permissions and privileges
Strong password policies with regular audits
Strict least-privilege enforcement across all roles
Which example describes a software-related weakness?
Updated drivers from trusted OEM vendors
Encrypted backups stored offsite regularly
Locked server rooms with CCTV monitoring
Unpatched systems with known vulnerabilities
Which scenario illustrates an operating system vulnerability?
Running the latest LTS release with auto-updates
Deploying the current OS patched within 24 hours
Enforcing kernel lockdown and secure boot
Using unsupported OS versions without critical updates
Which mobile device risk is commonly highlighted?
Elimination of vulnerabilities through monthly resets
Guaranteed carrier-level encryption by default
Reliance on OEMs causing delayed security updates
Immediate OEM patch delivery for every model
Which physical risk increases exposure to data loss?
Locked cabinets and asset tracking tags
Theft of equipment or loss of sensitive USB devices
Biometric access control with visitor logs
Secure courier handling for hardware returns
Risk Severity is defined by which formula?
Impact of Loss divided by Recovery Time
Probability of Occurrence multiplied by Impact of Loss
Threat Likelihood minus Asset Value
Vulnerability Count plus Control Strength
Match the probability descriptions to their labels.
Very Likely: approximately once or more per day
Likely: approximately every week or month
Unlikely: approximately every year
Which impact definition aligns with 'Major'?
Minimal operational or financial disruption
Significant disruption, financial loss, reputational damage
Minor inconvenience with reversible outcomes
Catastrophic loss threatening business viability
What is the primary purpose of a Vulnerability Assessment Report?
To document incident response post-breach only
To identify, classify, and prioritize vulnerabilities
To inventory hardware without security context
To train users without technical findings
Which tool-output pairing is correct for assessing weaknesses?
Port scanners identify open and exploitable ports
Website vulnerability scanners test for SQLi and XSS
Password audits evaluate strength and access controls
Vulnerability scanners measure network bandwidth usage
Which framework often guides web application testing?
IEEE 802.11 wireless standards
OWASP Top 10 covering common threats
ITIL service lifecycle processes
NIST SP 800-171 baseline mappings
Which strategic document logs each vulnerability, including its severity and tracks remediation?
Asset Inventory Sheet
Incident Postmortem Report
Change Management Request form
Risk Register used as master action plan
Which layer focuses on securing the asset itself through encryption and robust backup procedures?
Physical security foundation elements
Network perimeter segmentation rules
Data protection for encryption and backups
System endpoint hardening steps
Which controls are typically part of physical security in a layered framework?
Biometric or card entry systems
Site security locks and CCTV
Packet filtering firewalls
Protected cabling and cabinets
Which principle should guide authentication and access control configurations?
Defense in depth everywhere
Zero trust for external users
Principle of least privilege
Encrypt everything by default
Which items best represent system/host security activities?
Anti-virus with signature and heuristics
MAC address filtering
Regular patching schedules
Operating system hardening
Which firewall technique inspects each packet against a predefined ruleset?
Packet filtering and inspection
Network address translation process
Application layer awareness filter
Stateful deep packet offloading
What is the role of Network Address Translation (NAT) in security?
Encrypts wireless traffic end-to-end
Hides internal device addresses
Blocks all inbound connections
Enforces certificate pinning
Which statements about symmetric and asymmetric encryption are correct?
Symmetric uses the same key for both directions
Asymmetric encrypts with the public key and decrypts with the private key
Symmetric is commonly used for full disk encryption
Asymmetric is preferred for hashing user passwords
Which use case aligns with asymmetric encryption for protecting data in transit?
DRM for licensed media files
Incremental backup routines
HTTPS with TLS securing web traffic
Full file and folder encryption
Which authentication method uses encrypted tickets and never transmits passwords over the network?
SAML assertions
RADIUS server
OAuth 2.0 tokens
Kerberos protocol
What is the main purpose of architecture reviews and control audits?
Provide long-term data archival only
Generate vendor marketing materials
Replace the need for firewalls entirely
Verify controls are designed and operating
Which statements accurately describe key report types in control audits?
Internal control audit logs summarize routine monitoring of controls
TOR reports focus on anonymizing web traffic for users
Third-party design reviews identify flaws before implementation
Penetration test reports assess real-world defenses via simulated attacks
During identification, which activity best indicates a possible security incident?
Restoring services from backups
Monitoring unusual network traffic
Writing recommendations for management
Patching vulnerable applications
Which actions belong to the containment phase?
Define roles and responsibilities
Remove malware remnants
Quarantine affected systems
Disconnect compromised devices
Eradication primarily involves which set of tasks?
Quarantining devices for isolation
Updating controls and removing malware
Imaging drives to preserve evidence
Restoring services to normal state
Recovery is best described as:
Analyzing logs for attacker paths
Returning systems to normal operations
Documenting a detailed incident timeline
Agreeing on packet capture methodology
In the lessons learned phase, which outcome is most appropriate?
Isolation of compromised endpoints
Live capture of volatile memory data
Formal post-incident analysis for improvements
Immediate malware eradication steps
Desktop forensics prioritises which first step to preserve evidence integrity?
Confiscation of devices
Scan routers and firewalls
Review business impact
Push synthetic test traffic
Why is system imaging critical in desktop forensics?
It pushes test traffic to detect issues
It creates a bit-for-bit copy for analysis
It restores affected systems from backups
It updates controls to prevent recurrence
Which risk is unique to live forensics on running systems?
Accidentally blocking network access
Overlooking the root cause in reporting
Changing or corrupting volatile evidence
Missing logs from core switches
Network forensics commonly uses which pair of tool approaches?
Device confiscation procedures
Drive imaging of endpoints
Active tests that push traffic
Passive monitoring, such as packet sniffers
What is the primary purpose of a post-incident forensic report?
Provide a definitive account from detection to resolution
Restore services to normal operations quickly
Perform packet sniffing across live traffic
Capture only volatile memory from endpoints
Which contents should a thorough post-incident report include? Select all that apply.
Scope and Impact assessment
Response Actions Taken summary
Root Cause Analysis details
Live memory dump methodology
Which sequence best represents the continuous improvement cycle shown in the diagram for moving from reactive to proactive security?
Incident Response → Protective Controls → Vulnerability Management → Threat Intelligence
Threat Intelligence → Vulnerability Management → Protective Controls → Incident Response
Vulnerability Management → Threat Intelligence → Incident Response → Protective Controls
Protective Controls → Incident Response → Threat Intelligence → Vulnerability Management
In the diagram, which activities directly support a proactive, intelligence-led resilience posture? Select all that apply.
Control audits validating safeguards
Vulnerability assessments across critical assets
Post-incident reports only after breaches
Threat reports that inform emerging risks
What is the primary role of security reports in the depicted framework?
Static documentation of past incidents
Endpoints concluding the security process
Catalysts that fuel continuous improvement
Compliance artifacts for annual audits
Which action is most appropriate during the containment phase of incident response?
Conducting a post-incident review
Publishing a public statement about the incident
Isolating impacted systems from the network
Erasing all affected data immediately
What is the primary risk when using outdated software versions in an enterprise?
Reduced hardware compatibility
Increased vulnerability to exploits
Higher licensing costs
Slower user interface performance
Which method best helps prevent unauthorized access to sensitive data?
Allowing shared passwords for convenience
Implementing least privilege access controls
Disabling all encryption protocols
Using default system configurations
