NEW
Font size
Worksheetsndc+ca
Total questions: 40
Worksheet time: 20mins
Which firewall inspects traffic only based on IP addresses and ports?
Stateful firewall
Packet filtering firewall
Application firewall
Circuit gateway
Which control is intended to discourage violations rather than detect them?
Preventive
Detective
Deterrent
Corrective
Which iptables table is responsible for Network Address Translation?
FILTER
RAW
MANGLE
NAT
Which term describes an attack that goes undetected by an IDS?
False positive
False negative
True positive
True negative
Which document lists risks, controls, and treatment decisions?
Audit charter
Risk register
ISMS policy
SoA
Which port is used by Secure Shell (SSH)?
21
22
23
25
Which phase of audit formally communicates findings to management?
Planning
Assessment
Reporting
Follow-up
Which IDS type runs directly on the monitored host?
Network-based
Signature-based
Host-based
Anomaly-based
NAT is MOST effective in reducing exposure of:
Encryption keys
Internal IP structure
Firewall rules
Routing tables
Which command-line utility captures live network packets?
Snort
tcpdump
Netcat
Nikto
A firewall validates packets using session information stored dynamically. This firewall is:
Packet filtering
Circuit-level
Stateful
Proxy
Audit logs exist but are never reviewed. Which control weakness exists?
Preventive
Detective
Corrective
Administrative
Which iptables chain handles packets generated by the local system?
INPUT
FORWARD
PREROUTING
OUTPUT
Cyber insurance taken to cover ransomware loss is an example of:
Risk mitigation
Risk avoidance
Risk acceptance
Risk transfer
An IDS generates alerts whenever legitimate traffic spikes during business hours. The issue is most likely:
False negatives
Weak firewall
Poor baseline
Signature mismatch
Which IDS detection technique relies on deviation from normal behavior?
Signature
Rule-based
Anomaly
Heuristic
A DMZ is BEST described as:
Trusted internal zone
Untrusted external zone
Isolated buffer network
Encrypted tunnel
Which audit evidence carries the HIGHEST reliability?
User confirmation
Management assertion
System-generated logs
Policy documentation
Which Snort component formats alerts and logs?
Sniffer
Preprocessor
Detection engine
Output module
Firewall rules that allow only required services reflect which principle?
Defense in depth
Least privilege
Due care
Separation of duties
An IPS differs from IDS mainly because IPS:
Detects attacks faster
Works only on signatures
Blocks traffic automatically
Stores logs centrally
Which audit phase focuses on testing controls?
Planning
Assessment
Reporting
Closure
Which firewall generation introduced application-layer inspection?
First
Second
Third
Fourth
Multiple IDS alerts for normal activity indicate poor:
Network design
IDS tuning
Encryption
Firewall placement
Which iptables target drops packets silently?
ACCEPT
LOG
DROP
REJECT
Selecting 60 systems from 3000 during audit introduces:
Inherent risk
Control risk
Sampling risk
Detection risk
Which control provides traceability of user actions?
Authentication
Authorization
Logging
Encryption
Which IDS placement cannot block traffic?
Inline
Passive
Proxy-based
Gateway-based
Traffic flooding using compromised machines worldwide is known as:
DoS
Reflection attack
DDoS
Spoofing
IDS effectiveness in anomaly detection depends MOST on:
Signature updates
Hardware speed
Baseline accuracy
Packet size
Developers have write access to production systems. What is the PRIMARY audit concern?
Confidentiality
Availability
Lack of segregation of duties
Weak firewall
An IDS misses a genuine attack because traffic is encrypted. This is a:
False positive
False negative
True positive
True negative
Firewall rules placed incorrectly cause later rules to never execute. This issue is called:
Rule chaining
Rule shadowing
Rule escalation
Rule bypass
Auditor recommends separating dev, test, and production environments. This protects:
Availability
Confidentiality
Integrity
Authentication
Organization knowingly accepts flood risk due to business location. This is:
Risk mitigation
Risk avoidance
Risk transfer
Risk acceptance
Which control ensures recovery after ransomware attack?
IDS
Antivirus
Backup and restore
Firewall
Anomaly-based IDS generates excessive alerts. What should be corrected FIRST?
Signature database
Baseline definition
Firewall rules
Packet filtering
Which iptables chain processes packets routed through the system?
INPUT
OUTPUT
FORWARD
POSTROUTING
Which audit risk exists regardless of control effectiveness?
Control risk
Detection risk
Inherent risk
Sampling risk
Auditor verifies antivirus on a subset of endpoints due to time constraints. Method used is:
Compliance testing
Continuous auditing
Audit sampling
Risk assessment
