WorksheetsGeneral Security Concepts Part 2
Total questions: 30
Worksheet time: 10mins
Which of the following is an example of a preventive control?
Antivirus logs
Security awareness training
Firewall blocking malicious traffic
Incident investigation reports
Detective controls are designed to?
Prevent security incidents from happening
Recover systems after an attack
Restrict user permissions
Identify and alert on suspicious activity
Which control type enforces policies through people and procedures?
Administrative control
Physical control
Technical control
Technical control
In the CIA triad, what does integrity ensure?
Only authorized users can access the data
Data is encrypted during transmission
Data is accurate, complete, and unaltered
Systems are segmented to limit attacks
A security control that automatically removes malware after detection is:
Preventive
Detective
Physical
Corrective
Which concept ensures users have only the access they need to perform their job?
Least Privilege
Defense in Depth
Micro-Segmentation
Separation of Duties
Which security control is an example of a physical control?
Firewall
Biometric access
Patch management
SIEM monitoring
What is the main purpose of network segmentation?
Encrypt all traffic
Detect unauthorized logins
Limit the spread of attacks within the network
Automate patching processes
Which process ensures changes to systems are reviewed, approved, and documented before implementation?
Incident Response
Patch Management
Change Management
Vulnerability Scanning
Which activity is part of decommissioning a device?
Updating the asset inventory
Installing a new patch
Enabling remote access
Segmenting the network
What is the purpose of configuration enforcement?
To prevent lateral movement of attackers
To ensure devices comply with secure configuration standards
To detect malware
To encrypt data in transit
Which control type directly involves technical tools like firewalls or EDR?
Administrative
Physical
Technical
Corrective
Why is hardening a system important?
It improves network speed
It reduces the system’s attack surface
It ensures users can access all features
It prevents power outages
Which is an example of an administrative control in change management?
Disabling unused ports
Isolating infected devices
Applying a patch to a server
Documenting and approving a configuration change
Multi-factor authentication is primarily an example of which security principle?
Least privilege
Defense in Depth
Segmentation
Encryption
What is the primary purpose of change management in cybersecurity?
To encrypt sensitive data
To patch vulnerabilities automatically
To control and document changes to systems and processes
To segment the network
A security team wants to detect unusual network traffic patterns and potential intrusions. Which type of control are they implementing?
Detective control
Corrective control
Preventive control
Physical control
Which fundamental security principle ensures that users only have the minimum access necessary to perform their job?
Segmentation
Least Privilege
Isolation
Zero Trust
What is the primary goal of change management?
To manage changes with minimal disruption to services
To allow unrestricted system modifications
To implement changes without approval
To create more work for IT staff
What type of change requires the least documentation and approval?
Standard Change
Emergency Change
Major Change
Normal Change
Which tool is commonly used to track and manage changes?
Firewall
IDS
Change Management System (CMS)
VPN
What does a Change Advisory Board (CAB) do?
Designs system architecture
Implements emergency changes
Monitors network traffic
Reviews, assesses, and approves changes
What is the main focus of change evaluation?
Approving changes without risk assessment
Assessing success and lessons learned from a change
Ignoring post-change issues
Implementing changes immediately
A rollback plan is important because:
It provides a way to restore systems if the change fails.
It ensures changes are permanent
It avoids documentation
It delays implementation
Why is communication important in change management?
To avoid documenting changes
To keep stakeholders informed about potential impact and schedule
To bypass approval processes
To delay implementation
Which step ensures that changes do not disrupt business operations after implementation?
Post-Implementation Review
Change Request Submission
Ad-hoc Deployment
Risk Ignoring
Which method reduces risk before implementing a change?
Implementing directly in production
Delaying communication
Testing in a controlled environment
Ignoring dependencies
Which document is crucial for auditing change management processes?
Backup Files Only
Change Logs
Firewall Rules Only
Server Inventory
Risk assessment in change management includes?
Ignoring stakeholder concerns
Immediate deployment
Identifying potential issues and their impact on systems and users
Avoiding documentation
Which of the following is a key metric for evaluating change management effectiveness?
Number of changes implemented without incidents
Number of assets purchased
Server uptime only
Number of employees
