WorksheetsCySA+ Cegage ch 5
Total questions: 20
Worksheet time: 10mins
Which types of indicators are focused on detecting a successfully completed attack and show how it happened?
IOC
IOD
IOA
IOZ
Which technique of file analysis uses debuggers to watch the behavior of a file?
Federated
Open
Dynamic
Static
Which of the following is a remote online structure for sending commands to infected devices?
C&D
C&C
C&A
R&C
Which of the following remote sandboxing tools inspects items with over 70 antivirus scanners and URL/domain blocklisting services?
Joe Sandbox
SSDT View
Cuckoo Sandbox
VirusTotal
Which website serves as a central repository to identify IP addresses that have been reported as being associated with malicious activity online?
WHOIS
AbuseIPDB
CERN-X
WEBx
Which of the following logging levels accumulates all logging information?
ALL
TRACE
DEBUG
INFO
Which of the following email defenses uses a digital signature?
DKIM
SPC
DMARC
It depends on whether or not the email payload has been encrypted.
Which of the following is NOT correct regarding forwarding emails?
The best policy is to only forward highly sensitive emails.
Employees may decide to auto-forward corporate emails to utilize enhanced spam filtering.
Forwarded emails may not be available for eDiscovery.
Unauthorized users could access forwarded emails.
Which of the following is NOT correct about an email header?
As email is transferred from MTA to MTA, information is added to the email header.
Email headers are encrypted to prevent someone from altering the contents.
The email header contains information about the sender, recipient, email’s route through MTAs, and various authentication details.
Each MTA along the path adds its own information to the top of the email header.
Which tool would a threat actor use in malware to generate random dynamic URLs?
DGA
RSA
X-SPING
RCSC
Why would a threat actor choose Windows Command Shell over PowerShell?
Windows Command Shell is being deprecated and will no longer be supported in future versions of Microsoft Windows products.
Using PowerShell in malware requires a complicated registry hack.
Windows Command Shell commands can be invoked without starting a new identifiable process.
Windows Command Shell is faster than PowerShell.
Which email authentication method identifies who the MTA email servers are that have been authorized to send email for a domain?
TLL
MTU
MTA
SPF
Which of the following is NOT a limitation of UBA?
Threat actors will often target agents that collect data to disable them or bypass them so as to not raise an alarm.
UBA imposes a serious processing burden on systems and networks.
There are also challenges related to building a profile of users who access distributed applications.
Building a complete understanding of each and every application is difficult to achieve.
Which packet analyzer tool uses a CLI?
Wireshark
EtherApe
Tcpdump
ARC-View
Which of the following is NOT a reason flow analysis for cybersecurity is different than traditional network traffic flow analysis?
Eliminates monitoring agents
Uses deep packet inspection
Provides richer information
Executes faster
Which of the following tools is limited because information can be redacted for privacy purposes?
AbuseIPDB
WHOIS
Joe Sandbox
VirusTotal
Which of the following category of logs records detailed cybersecurity log information on suspicious behavior as well as any attacks that are detected and then blocked?
Firewall
Endpoint
Metadata
IDS/IPS
Which of the following is NOT a cybersecurity log management issue?
Only events that have previously been analyzed can be recorded in a log.
Log formats can vary.
There are conflicting interpretations of events by different devices.
All events are recorded.
Which of the following is the difference between a SIEM and a SOAR?
Only a SIEM can perform as both an IOC and an IOA.
A SIEM performs automated alerts and triggers to inform security personnel of critical issues while a SOAR can automatically take immediate action against a threat.
There are no appreciable differences between a SIEM and a SOAR.
SIEMs can only operate on endpoint devices while SOARs are network based.
Which of the following is NOT correct about EDR tools?
EDR tools can aggregate data from multiple endpoint computers to a centralized database so that security professionals can perform further IOC investigation.
They can perform more sophisticated analytics that identify patterns and detect anomalies to help detect unusual or unrecognized activities by performing baseline comparisons of normal behavior.
EDR tools require network-based sensors to gather data for analysis.
They have a similar functionality to HIDS of monitoring endpoint events and of HIPS of taking immediate action.
