wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CySA+ Cegage ch 5

Total questions: 20

Worksheet time: 10mins

Name
Class
Date
1.

Which types of indicators are focused on detecting a successfully completed attack and show how it happened?

a)

IOC

b)

IOD

c)

IOA

d)

IOZ

2.

Which technique of file analysis uses debuggers to watch the behavior of a file?

a)

Federated

b)

Open

c)

Dynamic

d)

Static

3.

Which of the following is a remote online structure for sending commands to infected devices?

a)

C&D

b)

C&C

c)

C&A

d)

R&C

4.

Which of the following remote sandboxing tools inspects items with over 70 antivirus scanners and URL/domain blocklisting services?

a)

Joe Sandbox

b)

SSDT View

c)

Cuckoo Sandbox

d)

VirusTotal

5.

Which website serves as a central repository to identify IP addresses that have been reported as being associated with malicious activity online?

a)

WHOIS

b)

AbuseIPDB

c)
  1. CERN-X

d)
  1. WEBx

6.

Which of the following logging levels accumulates all logging information?

a)

ALL

b)

TRACE

c)

DEBUG

d)

INFO

7.

Which of the following email defenses uses a digital signature?

a)

DKIM

b)

SPC

c)

DMARC

d)

It depends on whether or not the email payload has been encrypted.

8.

Which of the following is NOT correct regarding forwarding emails?

a)

The best policy is to only forward highly sensitive emails.

b)

Employees may decide to auto-forward corporate emails to utilize enhanced spam filtering.

c)

Forwarded emails may not be available for eDiscovery.

d)

Unauthorized users could access forwarded emails.

9.

Which of the following is NOT correct about an email header?

a)

As email is transferred from MTA to MTA, information is added to the email header.

b)

Email headers are encrypted to prevent someone from altering the contents.

c)

The email header contains information about the sender, recipient, email’s route through MTAs, and various authentication details.

d)
  1. Each MTA along the path adds its own information to the top of the email header.

10.

Which tool would a threat actor use in malware to generate random dynamic URLs?

a)

DGA

b)

RSA

c)

X-SPING

d)

RCSC

11.

Why would a threat actor choose Windows Command Shell over PowerShell?

a)

Windows Command Shell is being deprecated and will no longer be supported in future versions of Microsoft Windows products.

b)

Using PowerShell in malware requires a complicated registry hack.

c)

Windows Command Shell commands can be invoked without starting a new identifiable process.

d)

Windows Command Shell is faster than PowerShell.

12.

Which email authentication method identifies who the MTA email servers are that have been authorized to send email for a domain?

a)

TLL

b)

MTU

c)

MTA

d)

SPF

13.

Which of the following is NOT a limitation of UBA?

a)

Threat actors will often target agents that collect data to disable them or bypass them so as to not raise an alarm.

b)

UBA imposes a serious processing burden on systems and networks.

c)

There are also challenges related to building a profile of users who access distributed applications.

d)
  1. Building a complete understanding of each and every application is difficult to achieve.

14.

Which packet analyzer tool uses a CLI?

a)

Wireshark

b)

EtherApe

c)

Tcpdump

d)

ARC-View

15.

Which of the following is NOT a reason flow analysis for cybersecurity is different than traditional network traffic flow analysis?

a)

Eliminates monitoring agents

b)

Uses deep packet inspection

c)

Provides richer information

d)

Executes faster

16.

Which of the following tools is limited because information can be redacted for privacy purposes?

a)

AbuseIPDB

b)

WHOIS

c)

Joe Sandbox

d)

VirusTotal

17.

Which of the following category of logs records detailed cybersecurity log information on suspicious behavior as well as any attacks that are detected and then blocked?

a)

Firewall

b)

Endpoint

c)

Metadata

d)

IDS/IPS

18.
  1. Which of the following is NOT a cybersecurity log management issue?

a)
  1. Only events that have previously been analyzed can be recorded in a log.

b)
  1. Log formats can vary.

c)
  1. There are conflicting interpretations of events by different devices.

d)
  1. All events are recorded.

19.

Which of the following is the difference between a SIEM and a SOAR?

a)

Only a SIEM can perform as both an IOC and an IOA.

b)

A SIEM performs automated alerts and triggers to inform security personnel of critical issues while a SOAR can automatically take immediate action against a threat.

c)

There are no appreciable differences between a SIEM and a SOAR.

d)

SIEMs can only operate on endpoint devices while SOARs are network based.

20.

Which of the following is NOT correct about EDR tools?

a)

EDR tools can aggregate data from multiple endpoint computers to a centralized database so that security professionals can perform further IOC investigation.

b)

They can perform more sophisticated analytics that identify patterns and detect anomalies to help detect unusual or unrecognized activities by performing baseline comparisons of normal behavior.

c)

EDR tools require network-based sensors to gather data for analysis.

d)

They have a similar functionality to HIDS of monitoring endpoint events and of HIPS of taking immediate action.