WorksheetsModule 3: Mitigating Threats
Total questions: 10
Worksheet time: 5mins
Which organization maintains the "Common Vulnerabilities and Exposures" (CVE) list?
SANS Institute
The Mitre Corporation
Cisco Talos
FIRST
The "CIA Triad" is a conceptual foundation for information security. What does "CIA" stand for?
Control, Intelligence, and Auditing
Compliance, Inspection, and Authentication
Connectivity, Infrastructure, and Access
Confidentiality, Integrity, and Availability
What is the primary responsibility of a network security professional?
Repairing physical hardware failures only
Managing company payroll systems
Maintaining data assurance and ensuring information integrity and confidentiality
Designing customer-facing websites
How many network security domains are specified by the ISO/IEC standard mentioned in the module?
7
21
10
14
Which security policy identifies acceptable network applications and the ramifications of policy violations?
Acceptable Use Policy (AUP)
Incident handling procedures
Remote access policy
Password policy
Which software allows IT teams to implement security settings on all employee-owned devices that connect to the company network?
Password recovery software
Forensic analysis software
Mobile Device Management (MDM) software
Packet crafting software
Which platform is a cloud-based security operations platform that integrates multiple security functions into a single view?
John the Ripper
FireEye Helix
Wireshark
Cisco Catalyst
What are the four phases of a coordinated response to a worm attack?
Detection, Analysis, Response, Recovery
Identification, Authentication, Authorization, Accounting
Scanning, Exploitation, Lateral Movement, Exfiltration
Containment, Inoculation, Quarantine, and Treatment
What Cisco IOS feature allows users to control the flow of traffic handled by the route processor to prevent it from being overwhelmed?
Management plane
Data plane
Control Plane Policing (CoPP)
Security plane
What is one of the first signs that a network may be undergoing a Denial of Service (DoS) attack?
Large numbers of user complaints about unavailable resources or slow performance
A sudden decrease in the number of firewall logs
Unusually high download speeds for all users
All internal emails being automatically encrypted
