click below
click below
Normal Size Small Size show me how
Stack #4695185
| Question | Answer |
|---|---|
| It includes how to handle attachments, through filtering, personal use of the e-mail system, language restrictions, and archival requirements | |
| Which of the following is the difference between identification and authentication of a user? | > Identification tells who the user is, and authentication proves it. |
| It is generally defined as the probability that an event will occur. | > Risk |
| A network administrator uses an RFID card to enter the datacenter, a key to open the server rack, and a username and password to logon to a server. These are examples of which of the following? | > Multifactor authentication |
| > Remove inheritance from the payroll folder | |
| It identifies all the ways that the system can be remotely accessed and what is in place to ensure that access is from only authorized individuals | > Remote Access |
| Thirdie opens his fitness tracking app to start logging a workout. The app crashes, and he is unable to log his workout. | > Availability |
| A network administrator has purchased two devices that will act as failovers for each other. Which of the following concepts does this BEST illustrate? | > Availability |
| It is the term utilized for a wide extend of malicious exercises fulfilled through human interactions. | > Social Engineering Attacks |
| It is a process of converting encoded/encrypted data in a form that is readable and understood by a human or a computer. | > Decryption |
| It is the fraudulent practice of sending emails purporting to be from reputable companies in order to induce individuals to reveal personal information, such as passwords and credit card numbers. | > Phishing |
| There is a possibility that the cookies which are downloaded are infected ones and the attachments which are downloaded are also the victim of them. | > Cookies and attachments |
| > Botnets are a subset of malware which are used as part of DDoS attacks. | |
| It is a method used to gain access to data, systems, or networks, primarily through misrepresentation. | > Social Engineering |
| These are a subclass of denial of service (DoS) attacks. | > Distributed denial of service |
| It is unwanted software that infiltrates your computing device, stealing your internet usage data and sensitive information. | > Spyware |
| This term is seed very basically and widely in the computer programming and security. There is a thing where some problem, over burns the boundaries of the user and overwrite that's adjunct memory | > Buffer overflow |
| It is a computer virus that contains a variety of mechanisms specifically coded to make its detection and decryption very difficult. | > armored virus |
| It involves multiple connected online devices, collectively known as a botnet, which are used to overwhelm a target website with fake traffic. | > Distributed denial of service |
| It is a type of malware that constantly changes its identifiable features in order to evade detection. | > Polymorphic Malware |
| It is where the malicious script comes from the current HTTP request. | > Reflected XSS |
| These are used to prevent email spam | > Anti-spam |
| It is a collection of updates and fixes, called patches, for an operating system or a software program. | > service pack |
| Which passwords below would not be strong passwords? | > 123456789 |
| It enables the tracking of all interactions through which data, files or applications are stored, accessed or modified on a storage device or application. | > Auditing |
| It is the opposite of a whitelist. | > Blacklisting |
| It alludes to all computer system's equipment, firmware and computer program components that combine to supply the system with a secure environment. | > trusted computing base |
| It is the textual, visual, or aural content that is encountered as part of the user experience on websites. | > Web content |
| It provides services for computers connected to a network. | > Network operating system |
| It addresses any information that is protected against unwarranted disclosure. | > Sensitive data |
| It is the quality or state of being exposed to the possibility of being attacked or harmed, either physically or emotionally. | > Vulnerability |
| It is a set of rules applied by the owner, creator or administrator of a network, website, or service | > Acceptable User Policy |
| A security administrator notices that a specific network administrator is making unauthorized changes to the firewall every Saturday morning. Which of the following would be used to mitigate this issue so that only security administrators can make changes | > Least privilege |
| Are intended to prevent an incident from occurring by locking out unauthorized intruders. | > Preventive controls |
| It is how are all the security programs reviewed and how frequently | > Information Security Auditing |
| A return to an ordinary state of wellbeing, intellect, or quality. | > Recovery |
| The documents you don't need to keep physical copies of forever | > Fast-food chain receipt |
| It is a well-known, venerable model for the development of security policies used in identifying problem areas, along with necessary solutions in the arena of information security. | > CIA Triad |
| A company recently implemented a TLS on their network. The company is MOST concerned with: | > Confidentiality |
| This attack is the technique in which some code injection method is used. | > SQL injection |
| It is a program named after the Trojan horse story in Greek mythology. | > Trojan Horse |
| It can lead to a huge drop in visitors of websites. | > URL hijacking |
| It is an unskilled individual who uses scripts or programs, such as a web shell, developed by others to attack computer systems and networks and deface websites. | > Script kiddie |
| It is used in home / personal as well as enterprise environments to protect the connection between a wireless device and Wifi network with a secret key. | > WPA |
| It is an incursion where someone tries to steal information that computers, smartphones, or other devices transmit over a network. | > Eavesdropping Attacks |
| It is a form of credit-card fraud in which the perpetrator stands behind and looks over the shoulder of the victim as he or she withdraws money from an automated teller machine, memorizes the card details, and later steals the card | > Shoulder surfing |
| Sara, an attacker, is recording a person typing in their ID number into a keypad to gain access to the building. Sara then calls the helpdesk and informs them that their PIN no longer works and would like to change it. Which of the following attacks occur | > Impersonation |
| It is the method by which a URL is wrongly expelled from the look motor file and supplanted by another URL. | > URL hijacking |
| It is digital storage that is attached directly to a computer or a server. | > Direct-attached storage |
| It is collection of patches and hotfixes | > rollups |
| It arises when an application receives data from an untrusted source and includes that data within its later HTTP responses in an unsafe way. | > Reflected XSS |
| It is used to safeguard a user’s browser activities regardless of the website being accessed. | > Proxy server |
| The practice is the best defense against this type of attack, especially if coupled with a vulnerability management program. | > Patch management |
| These storage providers are responsible for keeping the data available and accessible, and the physical environment protected and running. | > Cloud storage |
| It is a computer program used to prevent, detect, and remove malware. | > Anti-malware |
| It serves as preventive control against denial-of-service (DoS) or distributed denial-of-service (DDoS) attacks. | > Flood guards |
| It is traffic that originates from outside the network’s routers and proceeds toward a destination inside the network. | > Ingress traffic |
| It is the protocol used to transfer data over the web. It is part of the Internet protocol suite and defines commands and services used for transmitting webpage data. | > HTTP |
| It is a network switch that contains a mapping of device information to VLAN. | > VLAN Management |
| It continuously monitors your network, looking for possible malicious incidents and capturing information about them. | > Intrusion Prevention System |
| It includes verifying the access points that are on the network, identifying any that shouldn't be there or have security issues, and detecting attacks on APs/clients. | > Wireless Intrusion Prevention System |
| It is a type of cloud computing distributes a full computer infrastructure via the web or Internet. | > IaaS |
| 802.11n was adopted | > 2009 |
| It was included as part of the original IEEE 802.11 standard and was intended to provide privacy. | > WEP |
| It can include specifications such as voltages, pin layout, cabling, and radio frequencies. | > Physical Layer |
| SAML stands for | > Security Assertions Markup Language |
| It is sometimes known as a generic account | > Shared account |
| It permits for adaptability, they also present challenges, including the failure to tie a person to an activity made whereas logged in. | > Shared account |
| It permits a remote access server to connect with an authentication server to determine if the user has access to the system | > RADIUS |
| It is easy to set up, it is considered weak encryption technology. | > Point-to-Point Tunneling Protocol (PPTP) |
| It dictates the character and length requirements, is often paired with expiration and password history rules that set parameters on when passwords need to be changed and when a password can be reused, if at all. | > Password complexity |
| It stores, organizes, and gives get to data in a registry | > LDAP |
| It grants access to the server based on the credentials supplied – simple user/pass authentication is not secure and is not suitable for authentication without confidentiality protection. | > Kerberos |
| It is a communications protocol that allows for the movement of data from one network to another | > Tunneling |
| It uses different types of characters in unique ways to increase security. | > Complex password |
| These are utilized by the beneficiary to decode a message that's encrypted employing a public key. | > Private Key |
| It could be a cryptographic key that can be dispersed to the open and does not require secure capacity | > Public Key |
| This incorporates managing with the era, trade, capacity, use, crypto-shredding (annihilation) and substitution of keys | > Key Management |
| The SSL is alternative to CRL | > False |
| It is the use of a Digital Certificate to identify a user, machine, or device before granting access to a resource, network, application, etc. | > Certificate authentication |
| These are usually stand-alone offline CAs like root CAs. | > Private CA |
| PKI Components except: | > Certificate Renovation List |
| It is HTTP-based. | > OCSP |
| A Certificate Trust Chain is a fraudulent certificate | > False |
| A small room with an entry door on one wall and an exit door on the opposite wall. | > Mantrap doors |
| Attendees are taken away from their usual roles and, for at least a few hours, take part in a workshop which sees an instructor lead them through the ins-and-outs of at least one security topic. | > Classroom-based training |
| It protects against employee theft and dishonesty. | > Bonded personnel |
| It is known as defense-in-depth or a layered security approach. | > Physical security |
| It is goal of physical security that focus on tangible assets | > Safeguarding physical assets |
| The following are Goals of Physical Security except | > Protecting nothing |
| They typically take the form of posters on topics such as secure passwords, handouts covering phishing scams or videos explaining things like the dangers of public wi-fi. | > Visual aids |
| It requires personal information controllers to take extra precaution when dealing with third parties. | > Due Diligence |
| The practice of reducing the electromagnetic field in a space by blocking the field with barriers made of conductive or magnetic materials. | > EMI shielding |
| A line of armored and alarmed cable under continuous monitoring and utilizing protected terminals at both ends | > Protected distribution |
| Set of procedures for identifying live hosts, ports, and services, discovering Operating system and architecture of target system. | > Scanning |
| These is how numerous clients will be influenced | > Affected users |
| A software environment is the whole of the distinctive points where an unauthorized client can attempt to enter information to or extricate information from an environment | > Attack surface |
| It is the degree to which of something, especially a piece of content or information, can be found in a search of a file, database, or other information system. | > Discoverability |
| Estimates the cost of recovering from a harmful event. | > Impact analysis |
| It could be a very particular sort of hazard, and it is characterized as an activity or occurrence that may result in a breach within the security, blackout, or debasement of a system by abusing known or obscure vulnerabilities | > Threat |
| The process by which an organization introduces specific measures to minimize or eliminate unacceptable risks associated with its operations. | > Risk mitigation |
| A tool (hardware or software) used to capture and analyze signals and data traffic over a communication channel. | > Sniffer |
| The plan standards are detailed clearly, and in-depth security control details are by and large reported in autonomous records | > Security architecture |
| The fact of accepting the identified risk and not taking any other action in order to reduce the risk because we can accept its impact, the possible consequences | > Risk acceptance |
| These are situations where the people involved had no injuries but could have been potentially harmed by the risks detected. | > Near misses |
| It includes planning what to do to prevent a data breach or attack from happening in the first place. | > Preparation |
| Detect and save malicious code from affected systems and media is part of "Guidelines for Recovering from a Security Incident". | > True |
| An event that may indicate that an organization's systems or data have been compromised or that measures put in place to protect them have failed. | > Security Incident |
| It involves replacing hardware in the case of a physical security incident. | > Recovery Methods |
| A good incident report has 4 elements | > False |
| These are incidents that need to be communicated across an organization to raise awareness of any harm that may happen. | > Adverse events |
| An organization must be able to effectively handle an attack, remove the threat, and start recovering affected systems and data. | > Containment, eradication, and recovery |
| This is the last procedure to be followed by the computer forensic team | > Computer Forensics |
| Pretending to be someone you are not. | > Identity theft |
| It contains even fewer facilities than a Warm Site. | > Cold Site |
| It is a course of action designed to help an organization respond effectively to a significant future event or situation that may or may not happen | > contingency plan |
| It is the process involved in creating a system of prevention and recovery from potential threats to a company | > BCP |
| RTO stand for: | > Recovery Time Objective |
| It is analyzing are the operational and financial impacts of a disruption of business functions and processes | > BIA |
| It is a plan devised for an outcome other than in the usual (expected) plan | > Backout Contingency Plan |
| This is one of the most fundamental objectives of business continuity management | > Assess risks and impact |
| BIA stands for: | > Business Impact Analysis |
| It will outline the technologies, tools and protocols that are already in place to prevent or mitigate the effects of a disaster. | > Outline existing preventative measures |
| It backs up all selected files regardless of the state of the archived bit. | > Full backup |
| Everyone in the accounting department could print and sign checks. Internal audit has asked that only one group of employees may print checks while only two other employees may sign the checks. Which of the following concepts would enforce this process? | > Separation of Duties |
| It is a situation involving exposure to danger. | > Risk |
| It is the protection of people, property, and physical assets from actions and events that could cause damage or loss. | > Physical Security Attacks |
| It is a definition of what it means to be secure for a system, organization or other entity. | > Security policy |
| Mandatory vacations are a security control which can be used to uncover which of the following? | > Fraud committed by a system administrator |
| It should describe the requirements driving the change in sufficient detail to allow approvers and other officials to make an informed decision on the change request. | > Change documentation |
| It is someone without the proper authentication follows an authenticated employee into a restricted area. | > Tailgating |
| It is one of the fastest growing forms of malware; it encrypts data files and then demands a ransom to decrypt the files. | > Ransomware |
| It is a fraudulent Wi-Fi access point that appears to be legitimate but is set up to eavesdrop on wireless communications. | > Evil twin attack |
| Isn't limited to searching through the trash for obvious treasures like access codes or passwords written down on sticky notes. | > Dumpster diving |
| Which of the following could a security administrator implement to mitigate the risk of tailgating for a large organization? | > Only allow employees to enter or leave through one door at specified times of the day. |
| Joe, a security administrator, is concerned with users tailgating into the restricted areas. Given a limited budget, which of the following would BEST assist Joe with detecting this activity? | > Install a camera and DVR at the entrance to monitor access. |
| This attack is taken place, the attack mainly makes some efforts and has an aim to inject some XML tags into the SOAP message and hence he wants to modify the source of XML | > XML injection |
| It could be a shape of credit-card extortion in which the culprit stands behind and looks over the bear of the casualty as he or she pulls back cash from an computerized teller machine, memorizes the card subtle elements, and afterward takes the card | > Shoulder surfing |
| It is a process through which some or all the Internet activity initiated from a Web browser is naively encrypted. | > Encryption |
| It is to reduce security risk by eliminating potential attack vectors and condensing the system’s attack surface. | > Hardening |
| It indicates conditions that a reasonable application might want to catch | > Exception |
| It arises when an application takes some input from an HTTP request and embeds that input into the immediate response in an unsafe way. | > Reflected cross-site scripting |
| It is an input validation and error recovery at the browser | > Client-side validation |
| This protocol provides 128-bit encryption and is currently the leading security mechanism for protecting web traffic including banking, e-commerce, secure email, and essentially any other secure website that might be encountered. | > TLS |
| It refers to the detection of attacks by looking for specific patterns, such as byte sequences in network traffic, or known malicious instruction sequences used by malware. | > Signature-based |
| At this layer, routers are a crucial component used to quite literally route information where it needs to go. | > Network Layer |
| It means enabling a person to discover or learn something for themselves | > Heuristic |
| It is a firewall configuration used to secure hosts on a network segment. | > DMZ |
| It manages the delivery and error checking of data packets. | > Transport Layer |
| It is malware detection evaluates an object based on its intended actions before it can execute that behavior. | > Behavior-based |
| It was designed as the interim successor to WEP. | > WPA |
| Its security stance treats everything not given specific and selective permission as suspicious. | > Implicit deny |
| It can be used to access region-restricted websites, shield your browsing activity from prying eyes on public Wi-Fi, and more. | > Virtual Private Network |
| It is a password that can be only used one time. | > OTP |
| It is based on a time-sensitive ticket granting system. | > Kerberos |
| It should be defined for each administrative role and system within an organization, allowing for separation of duties and preventing too much power being placed in too few accounts. | > Privileged accounts |
| Which option is not a good trait for your password? | > Short password |
| PGP stands for | > Pretty Good Privacy |
| These are commonly used for two-factor authentication and have seen growing adoption by cloud application providers. | > TOTP |
| It controls the privileges and functions of an application. | > Service accounts |
| It controls how numerous days a client must hold up some time recently they can reset their password | > Minimum Password Age |
| It is the link between the authentication of a user’s identity and the authorization to use a service. | > SAML |
| The Certificate Chain is lack encryption | > False |
| It has the responsibility to validate the entity behind an SSL certificate request and, upon successful validation | > CA |
| PKI Components except: | > Hardware Store |
| Instead of automatically being shunted to a CRL, some CA’s have settings that renew certificates upon expiration date, though typically they re-verify identity | > Certificate Renewal |
| It is a list of certificates (or more specifically, a list of serial numbers for certificates) that have been revoked or are no longer valid, and therefore should not be relied upon | > Certificate Revocation List |
| It is the topmost Certificate Authority (CA) in a Certificate Authority (CA) hierarchy. | > Root CA |
| This multi-leveled hierarchy of trust. | > Certificate Trust Chain |
| An act of collecting available body of facts or information indicating whether a belief or proposition is true or valid. | > Evidence Collection |
| An object, quality, or event whose presence or occurrence indicates the probable presence or occurrence of something else. | > Signs |
| In Business Partners. Control data sharing and discourage unauthorized sharing. | > True |
| The act of telling someone officially about something, or a document that does this | > Notifications |
| An electrical device that utilizes a sensor to detect nearby motion. | > Motion detection |
| It ensures all users comply with guidelines. | > Rule-Based Training |
| In Business Partners. Control how shared data is backed up. | > True |
| The process of identifying someone or something or the fact of being identified. | > Identification systems |
| An arrangement that is accepted by all parties to a transaction. | > Agreements |
| It may stipulate certain types of encryption for all data in transit. | > ISA |
| It is to identify potential problems before they occur, or, in the case of opportunities, to try to leverage them to cause them to occur. | > Risk management |
| It is the evaluation or estimation of the nature, quality, or ability of someone. | > Assessment |
| A computer program used to retrieve information about users and groups on networked computers | > Network Enumerator |
| These is how much exertion and encounter are essential | > Exploitability |
| It probes a server or host for open ports | > Port Scanner |
| The quality of being able to be discovered or found | > Discoverability |
| All are importance of Vulnerability Assessments except: | > Late and inconsistent identification of threats and weaknesses in IT security |
| Its aspects are abstract; they either do not require measurement or cannot be measured because the reality they represent can only be approximated. | > Qualitative |
| It is defined as any event, condition or situation which attracts negative media attention or a negative profile for the workplace | > Sentinel |
| The process of identifying, managing, recording and analyzing security threats or incidents in real-time. | > Security Incident Management |
| Source and destination of systems and networks is part of "Guidelines for Recovering from a Security Incident" | > True |
| An organization ought to be prepared to bargain with a cybersecurity incident some time recently it happens and arrange all vital reaction methods in progress. | > Preparation |
| It seeks to give a robust and comprehensive view of any security issues within an IT infrastructure. | > Security Incident Management |
| It’s important to gather evidence about the incident to use later both for resolving the incident and in legal proceedings. | > Containment, eradication, and recovery |
| Neglect the results of the investigation | > False |
| Overloading a system with so many requests it cannot serve normal requests | > Denial of Service attack |
| All selected files that have changed since the last full backup are backed up. | > Differential backup |
| WRT stands for: | > Work Recovery Time |
| It is a group of individuals with defined roles and responsibilities and is responsible for maintaining the recovery procedures and coordinating the recovery and resumption of business functions, processes or systems. | > Recovery Team |
| It focusses on each BCP phase. | > Paper testing |
| You will also include the impact of each scenario: how much damage would be caused, how long the recovery would take, the cost of operational losses and so on. | > Assess risks and impact |
| It involves a set of policies, tools and procedures to enable the recovery or continuation of vital technology infrastructure and systems following a natural or human-induced disaster. | > Disaster Recovery Plan |
| It usually entails storing important data on a periodic basis on local storage devices, such as hard drives, DVDs, magnetic tapes, or CDs. | > Backup |
| Recovery teams need to know where and how to relocate operations, and with what resources | > Identify back-up locations and resources |
| Defines account limits for a set of users of one or more resources | > Company policy |
| A system of writing that prevents most people from understanding the message | > Cryptography |
| Should clearly identify how policy is enforced and how breaches/misconduct are handled | > Enforcement |
| SharePoint site where only the security team can modify permissions, all access centrally managed | > Mandatory access control |
| The state of keeping or being kept secret or private | > Confidentiality |
| Intended to identify and characterize an incident in progress by sounding an alarm/alerting guards | > Detective controls |
| Company implemented TLS on their network - MOST concerned with | > Confidentiality |
| Ads that get injected and can turn computers into botnets (e.g. Firefox incident) | > Malicious add-ons |
| Captures traffic then performs an offline brute force attack to discover the encryption key | > WEP |
| Any method by which users can bypass normal security and gain root/high-level access | > Backdoor Attacks |
| Timestamps and sequence numbers act as countermeasures against this attack type | > Replay |
| May not necessarily be bad; often used with ill intent | > Adware |
| Gives guardians the ability to set parameters for what can appear on a browser | > Parental controls |
| Employees bringing their own smartphones/laptops/tablets to connect to the secure corporate network | > BYOD |
| All computer system equipment, firmware, and program components combined to supply a secure environment | > trusted computing base |
| Best defense against attacks, especially coupled with vulnerability management | > Patch management |
| Could be a collection of patches and hotfixes | > service pack |
| Designed to detect unauthorized user activities, attacks, and network compromises | > Intrusion Detection Systems |
| Network traffic that begins inside the network and proceeds out to a destination outside the network | > Egress traffic |
| A firewall application installed on a server to protect network segments from other network segments | > Network firewall |
| A network security device that monitors and permits/blocks traffic based on security rules | > firewall |
| A firewall application installed on a host to protect it from network-based attacks | > Host firewall |
| Enhances port security by limiting the number of MAC addresses learned within a VLAN | > MAC limiting |
| Year 802.11ac was adopted | > 2014 |
| The act of creating a virtual version of hardware, storage devices, and network resources | > Virtualization |
| A device that acts as a reverse proxy and distributes traffic across several servers | > load balancer |
| Authentication protocol that uses plain text (unencrypted passwords) | > PAP |
| Provides centralized management/config of OS, applications, and user settings in Active Directory | > Group Policy |
| Which of the following is a strong password | > 2BorNotTwoB |
| A way of limiting access to a system or to physical or virtual resources | > Access control |
| Open and cross-platform protocol used for directory services authentication | > LDAP |
| Controls how many days a client must wait before they can reset their password | > Minimum Password Age |
| Temporary passcode generated using the current time of day as an authentication factor | > TOTP |
| What type of characters should you include in a password | > Letters, Numbers and Symbols |
| Technology that employs the use of SAML | > Single sign-on |
| A Certificate Renewal means a holder is no longer trusted (True/False) | > False |
| Alternative to CRL | > OCSP |
| Also called local CAs | > Private CA |
| The third party agent is called | > Key Escrow |
| Longer life cycles give attackers an advantage - this refers to | > Certificate Life Cycle |
| CA setting that renews certificates upon expiration instead of shunting to CRL, but re-verifies identity | > Certificate Renewal |
| Short for heating, ventilation, and air conditioning | > HVAC systems |
| Goal of physical security that focuses on access to your network | > Safeguarding physical assets |
| A staple in a CISO's arsenal that varies widely by provider | > Online security awareness training |
| Requires every visitor to sign in and out of the building | > Logging and visitor access |
| Act of collecting available facts/information indicating whether a belief or proposition is true | > Evidence Collection |
| Environmental/natural conditions that act as a barrier to communication | > Physical barriers |
| Layout design for server racks and computing equipment in a data center | > Hot and cold aisles |
| Business Partners: control how shared data is backed up (True/False) | > True |
| Types of Legal Requirements EXCEPT | > Nobody |
| Business Partners: control data sharing and discourage unauthorized sharing (True/False) | > True |
| Locates weaknesses in a system | > Vulnerability identification |
| Any attempt to expose, alter, disable, destroy, steal, or gain unauthorized access to an asset | > Attack |
| Automated tools that scan web apps from outside for vulnerabilities (XSS, SQLi, etc.) | > Vulnerability Scanners |
| An event caused by natural forces of the Earth causing great damage/loss of life | > Natural disaster |
| Process of identifying, quantifying, and prioritizing vulnerabilities in a system | > Vulnerability Assessment |
| Unified security design addressing necessities and risks in a scenario/environment | > Security architecture |
| Hardware/software tool used to capture and analyze signals/data traffic over a channel | > Sniffer |
| A person who finds and exploits weaknesses in computer systems/networks to gain access | > Hacker |
| Data that measures conditions before project start for later comparison | > Baseline |
| How much damage can be inflicted on our system | > Damage potential |
| "What steps were taken to resolve the incident" is part of Guidelines for Recovering from a Security Incident (True/False) | > True |
| Organization must effectively handle attack, remove threat, and start recovering systems/data | > Containment, eradication, and recovery |
| "Names and phone numbers of last responders" is part of Guidelines for Recovering from a Security Incident (True/False) | > False |
| Plans that address cybercrime, data loss, and service outages threatening daily work | > Incident Response Plan |
| Guidelines for Recovering from a Security Incident (Report) EXCEPT | > Methods used to detect the incident |
| Guidelines for Recovering from a Security Incident (Recover) EXCEPT | > Determine damage to facilities, hardware, systems, and networks |
| Stealing practical or conceptual information developed by another person or company | > Intellectual property theft |
| Application of investigation/analysis techniques to gather and preserve digital evidence for court | > Computer Forensics |
| "Deceive officials and stakeholders" is part of Guidelines for Recovering from a Security Incident (True/False) | > False |
| An integral part of today's disaster relief and recovery | > Incident response |
| Determines the maximum acceptable amount of data loss measured in time | > RPO |
| Instrumental in verifying design flaws, recovery requirements, and implementation errors | > Performing walkthroughs |
| Analyzing operational and financial impacts of a disruption of business functions/processes | > BIA |
| Should identify operational and financial impacts resulting from disruption of business functions | > BIA |
| Set of policies, tools, and procedures to recover/continue vital tech infrastructure after a disaster | > Disaster Recovery |
| A backup site that is up and running continuously | > Hot Site |
| Process of creating a system of prevention and recovery from potential threats to a company | > BCP |
| Performs additional analysis to ensure the BC solution fulfills organizational recovery requirements | > Parallel testing |
| It is to ensure that the information is protected against any unauthorized or accidental changes. | > Integrity |
| It has been used to strengthen password-based user authentication systems by considering the typing characteristics of legitimate users. | > Keystroke dynamics |
| These are pernicious pieces of computer code and applications that can harm your computer, as well as take your personal or money related data. | > Software-Based Attacks |
| The action or process of identifying the presence of something concealed. | > Detection |
| It takes a block of plain text and a key, and outputs a block of ciphertext of the same size. | > Block cipher |
| A network administrator has a separate user account with rights to the domain administrator group. However, they cannot remember the password to this account and are not able to login to the server when needed. Which of the following is MOST accurate in d | > Authentication |
| It is a malicious, self-replicating software program which affects the functions of software and hardware programs. | > Worms |
| An administrator notices an unusual spike in network traffic from many sources. The administrator suspects that: | > it is the beginning of a DDoS attack. |
| An administrator is assigned to monitor servers in a data center. A web server connected to the Internet suddenly experiences a large spike in CPU activity. Which of the following is the MOST likely cause? | > DoS |
| This attack falls into the category of the applications attacks as well since it is also associated to some applications. | > XML injection |
| It is a misuse of trust that causes issues with securing information or control. | > Transitive access |
| It is an attack where a user session is taken over by an attacker. | > Session hijacking |
| It specifically targets senior management that hold power in companies, such as the CEO, CFO, or other executives | > whaling |
| Physical documents must be incinerated after a set retention period is reached. Which of the following attacks does this action remediate? | > Dumpster Diving |
| It is the activity of sending advertisements by email to people who do not want to receive them | > Spamming |
| It is a process of protecting files, databases, and accounts on a network | > Data Security |
| It is the tool that facilitates the business regarding data processing while putting a special concern to some targeted operations. | > Auditing |
| It is the term used for analysis of computer-generated records for helping organizations, businesses or networks in proactively and reactively mitigating different risks. | > Log analysis |
| The formats or translates data for the application layer based on the syntax or semantics that the application accepts. | > Presentation Layer |
| It directly connected nodes are used to perform node-to-node data transfer where data is packaged into frames. | > Data Link Layer |
| It is used by network devices, including routers, to send error messages and operational information indicating, for example, that a requested service is not available or that a host or router could not be reached. | > ICMP |
| It referred to as internal cloud or corporate cloud. | > Private |
| It is concerned with electrically or optically transmitting raw unstructured data bits across the network from the physical layer of the sending device to the physical layer of the receiving device. | > Physical Layer |
| It is connection between machines is set up, managed, and terminal at layer 5. | > Session Layer |
| It is one of the most important aspects of an organization’s security posture. | > Account management |
| A company needs to supply centralized authentication for its wireless system. The wireless authentication system must coordinate with the directory back end. Which of the taking after could be a AAA solution that will give the specified wireless authentic | > RADIUS |
| For logging purposes only, it should not grant access to a client. | > Unauthenticated authentication |
| Ik4wLhung$4paTn4 is a | > Strong password |
| It is a procedure begins when a user files a certificate enrollment request with a CA. | > certificate enrollment |
| The OCSP is HTTP-based | > True |
| It provides certificates for intermediate CAs. | > Root CA |
| A sort of blacklist that instructs the RADIUS not to verify those certificates. | > Certificate Revocation List |
| It is used to store certificates and can potentially contain certificates from multiple CAs. | > Certificate Store |
| It doesn’t have strict guidelines in place to protect sensitive data. | > MOU |
| In Business Partners. Develop procedures for on-boarding and off-boarding of partners. | > True |
| The formal process for training and educating employees about IT protection. | > Security awareness |
| It is a written agreement that details the relationship between business partners, including their obligations toward the partnership. | > BPA |
| It is a commercial entity with which another commercial entity has some form of alliance. | > Business Partners |
| It refers to a geographic area containing a defined legal authority. | > Jurisdiction |
| It means that if the power is interrupted or fails, the door stays locked | > Fail secure |
| A type of self-replicated computer malware, which can be used to find out vulnerabilities | > Computer Worm |
| A unified security design that addresses the necessities and potential risks involved in a certain scenario or environment. | > Security architecture |
| Crime, arson, civil disorder, terrorism, war, biological / chemical threat, cyber-attacks, are examples of | > Man-made disasters |
| Tricking people into believing something that is not true. | > Scam |
| It is a formal recording of the facts related to an incident. | > Incident report |
| Copying, distributing, or using software that was not purchased by the user of the software. | > Software piracy |
| It is a structured methodology for handling security incidents, breaches, and cyber threats. | > Incident Response |
| After effectively handling a security incident, an organization should use the information learned from the incident to improve its current IRP. | > Post-incident activity |
| The following are guidelines for Recovering from a Security Incident (Recover) except | > Harden networks and servers. |
| It is an information technology term that refers to a system or component that is continuously operational for extended lengths of time. | > High availability |
| It describes the interval of time that might pass during a disruption before the quantity of data lost during that period exceeds the Business Continuity Plan’s maximum allowable threshold or “tolerance.” | > RPO |
| It is a business plan that describes how work can be resumed quickly and effectively after a disaster. | > Disaster Recovery Plan |
| It reviews the BCP's contents. | > Paper testing |
| It defines the maximum amount of time that a system resource can remain unavailable before there is an unacceptable impact on other system resources, supported mission/business processes. | > MTD |
| It determines the maximum tolerable amount of time that is needed to verify the system and/or data integrity. | > WRT |
| It describes the policy under which third-party organizations connect to your networks for the purpose of transacting business related to your company | > Extranet policy |
| In order to prevent and detect fraud, which of the following should be implemented? | > Job rotation |
| What isn't required to be secured? | > Intruder |
| It could be a sort of social engineering procedure utilized to get data such as individual identification numbers (PINs), passwords and other secret information by looking over the victim's shoulder | > Shoulder surfing |
| It allows hackers to employ a program which cycles through common words. | > Dictionary attack |
| It occurs when a cybercriminal eavesdrops on a secure network communication, intercepts it, and then fraudulently delays or resends it to misdirect the receiver into doing what the hacker wants. | > Replay Attacks |
| It is a person who gains unauthorized access to computer files or networks in order to further social or political ends. | > Hacktivists |
| 802.11g was adopted | > 2003 |
| It is used by enterprises to protect their employees/users from accessing and being infected by malicious Web traffic, websites and virus/malware. | > Web Security Gateway |
| 802.11b was adopted | > 1999 |
| The communications between a computing system are split into seven different abstraction layers | > OSI Model |
| This is the family of specifications for wireless local area networks (WLANs) developed by a working group of the Institute of Electrical and Electronics Engineers (IEEE). | > 802.11 |
| It is a unit of physical hardware or equipment that provides one or more computing functions within a computer system. | > Device |
| It is the security method added to WPA for wireless networks that provides stronger data protection and network access control | > WPA2 |
| June111998 is a | > Weak password |
| These are the most common form of authentication, and IT help desks spend a lot of time managing calls from users who cannot log on because they forgot their passwords, or their accounts have been compromised. | > Passwords |
| Every time the certificate is used to authenticate. | > Certificate Validation |
| It is that it uses a combine of keys to attain the basic security benefit. The key match comprises of private key and public key. | > PKI |
| A program that communicates with a Web application to find potential vulnerabilities within the application or its architecture | > Web Application Security Scanner |
| A software quality assurance activity in which one or several people check a program mainly by viewing and reading parts of its source code. | > Code review |
| It gives a spoken or written account of something that one has observed, heard, done, or investigated. | > Reporting Phase |
| It is vital to have a response plan in place before an incident occurs so that you can limit the damage caused by the event. | > Incident response |
| For digital damage, examine log files, identify compromised applications... | > Assess the damage |
| Planning establishes risk management processes and procedures that aim to prevent interruptions to mission-critical services | > Business Continuity |
| Onsite storage does not need internet access | > True |
| Kim has taken her A-Level exam and is waiting to get her results by email. By accident, Kim's results are sent to Karen. | > Confidentiality |
| Users are unable to connect to the web server at IP 192.168.0.20. Which of the following can be inferred of a firewall that is configured ONLY with the following ACL? PERMIT TCP ANY HOST 192.168.0.10 EQ 80 PERMIT TCP ANY HOST 192.168.0.10 EQ 443 | > It implements an implicit deny. |
| It is a simple, yet highly effective method of causing a DoS on a wireless LAN | > Jamming |
| It enables an administrator to configure individual switch ports to allow only a specified number of source MAC addresses ingress the port. | > Port Security |
| It is a technique used to modify the network address information of a host while traffic is traversing a router or firewall. | > Network Address Translation |
| These are inspections of an area where work is proposed, to gather information for a design or an estimate to complete the initial tasks required for an outdoor activity. | > Site Surveys |
| It is a cryptographic network protocol for operating network services securely over an unsecured network | > Secure Shell (SSH) |
| It can be recognized where several organizations have comparable necessities and very willing to share infrastructure so as to take in the benefits of cloud computing. | > Community |
| Should you give people your password? | > No |
| RADIUS stands for | > Remote Authentication Dial in User Service |
| What shouldn't your password consist of? | > Personal info |
| It is a procedure back up to removable media | > Private Key Protection Methods |
| One or more escrow agents can restore. | > Private Key Restoration Methods |
| The RADIUS server checks with the CA to affirm that the certificate is still substantial and hasn't terminated been revoked | > Certificate Validation |
| The CA needs to validate the identity of the applicant, which is typically done through credentials or by trusting another CA that has already validated the applicant. | > True |
| It gives an audible, visual or other form of alarm signal about a problem or condition. | > Alarms |
| Organization name is part of "Guidelines for Recovering from a Security Incident" | > False |
| In a later section, your plan will outline different types of disasters that could disrupt the business | > Assess risks and impact |
| Onsite storage has access to data from any location, via Internet or FTP | > False |
| These are the plans used by the bronze or operational teams following an incident which affects their ability to operate normally | > Business Recovery Plans |
| It is a commercial disaster recovery service that allows a business to continue computer and network operations in the event of a computer or equipment disaster. | > Hot Site |
| It prevents one party from denying actions they carry out. If proper authentication, authorization, and accounting have been established, a person cannot deny their own actions. | > Non-repudiation |
| It is an authentication method that identifies and recognizes people based on voice recognition or physical traits such as a fingerprint, face recognition, iris recognition, and retina scan | > Biometrics |
| It is a rogue wireless access point installed near a legitimate one for purposes of eavesdropping or phishing. | > Evil Twins |
| This attack is the type of an injection in which there are some malicious scripts inserted into the websites which are trusted ones by the users. | > Cross-site scripting |
| It is a physical or logical device used to capture keystrokes | > keylogger |
| These are programs written deliberately to vandalize someone's computer or to use that computer in an unauthorized way | > Software attacks |
| It is a server application or appliance that acts as an intermediary for requests from clients seeking resources from servers that provide those resources. | > Proxy server |
| WPS stands for | > WiFi Protected Setup |
| It allows a user on one system to login to a remote system and issue commands in a command window of the remote system. | > Secure Shell (SSH) |
| It is designed to monitor and manage the network traffic flow over a network. | > Network Monitoring Systems |
| It is an intrusion detection system for detecting both network and computer intrusions and misuse by monitoring system activity and classifying it as either normal or anomalous | > Anomaly-based |
| It allows users to connect to a network while allowing them to remain mobile. | > WLAN |
| It is a temporary passcode generated by an algorithm that uses the current time of day as one of its authentication factors. | > TOTP |
| It is another policy that automatically disables an account when a certain threshold of incorrect passwords is used to log in, requiring a user to recover access to their account with a new password or by satisfying other requirements, such as security qu | > Account lockout |
| Which of the following technologies employ the use of SAML? | > Single sign-on |
| CRT Stands for: | > Certificate Revocation List |
| CA stands for: | > Certificate Authority |
| PKI stands for: | > Public Key Infrastructure |
| It isn't a mandatory component of a PKI, but it improves the security of the PKI when implemented. | > HSM |
| A temporary rise of the water level, as in a river or lake or along a seacoast, resulting in its spilling over and out of its natural or artificial confines onto land that is normally dry. | > Water damage and flooding |
| In Business Partners. Don't set rules for third-party data backups. | > False |
| In Business Partners. Let employees know what they should and should not share. | > True |
| These are a system of one or more video cameras on a network that send the captured video and audio information to a certain place. | > Video surveillance |
| A formal way of collecting data and supposition in support of the pros and cons in any change or disruption to your business. | > Impact analysis |
| A system or plan that comes into operation in the event of something going wrong or that is there to prevent such an occurrence. | > Failsafe |
| It is defined as the process of extracting usernames, machine names, network resources, shares and services from a system. | > Enumeration |
| Data that measures conditions some time recently venture begin for later comparison. | > Baseline |
| The following are elements of a Good Incident Report except | > Incomplete |
| Is the chronological documentation or paper trail that records the sequence of custody, control, transfer, analysis, and disposition of physical or electronic evidence. | > Chain of Custody |
| Unidentified disaster recovery personnel are part of Goals of Business Continuity Plan | > False |
| It is the process by which an organization deals with a disruptive and unexpected event that threatens to harm the organization or its stakeholders | > Crisis management |
| Another crucial purpose of creating a BCP is identifying the various threats to your operations | > Assess risks and impact |
| Onsite storage has immediate access to data | > True |
| It ensures that systems perform adequately at any alternate offsite facility, without taking the main site offline. | > Parallel testing |
| Which of the following security concepts can prevent a user from logging on from home during the weekends? | > Time of day restrictions |
| It is an official record of events during the operation | > Log |
| Users report that they are unable to access network printing services. The security technician checks the router access list and sees that web, email, and secure shell are allowed. Which of the following is blocking network printing? | > Implicit deny |
| It creates an arbitrarily long stream of key material, which is combined with plain text bit-by-bit or character-by-character. | > Stream ciphers |
| The documents you need to keep physical copies of forever | > Marriage license |
| It should include information that identifies how security profiles will be applied uniformly across common devices | > Security Profiles |
| A user casually browsing the Internet is redirected to a warez site where a number of pop-ups appear. After clicking on a pop-up to complete a survey, a drive-by download occurs. Which of the following is MOST likely to be contained in the download? | > Spyware |
| A security administrator notices large amounts of traffic within the network heading out to an external website. The website seems to be a fake bank site with a phone number that when called, asks for sensitive information. After further investigation, th | > Phishing |
| It can also include malware removal capabilities. | > Antivirus |
| It is a general term for archiving data in electromagnetic or other forms for use by a computer or device. | > Data storage |
| It consists of at least six characters that are a combination of letters, numbers and symbols if allowed. | > strong password |
| It allows only identified programs to run. | > White listing |
| HOTP stands for | > HMAC based One Time Password Algorithm |
| A person employed to protect a building against intruders or damage. | > Security guards |
| It is a technique to test the software product or application with partial knowledge of the internal workings of an application. | > GRAY BOX TESTING |
| The process of collecting as much as information as possible about the target system to find ways to penetrate the system. | > Foot Printing |
| It should also be able to prioritize an incident according to its impact and recoverability and then notify the proper authorities about the breach. | > Detection and analysis |
| Manipulating data, e.g., changing banking records to transfer money to an account or participating in credit card fraud. | > Fraud |
| It is a process for identifying and developing new leaders who can replace old leaders when they leave, retire or die. | > Succession Planning |
| It ensures that the overall organization remains as secure as possible while providing the flexibility it needs to remain functional. | > Defense in depth |
| It defines rules of behaviors and guidelines for employees when using their own devices. | > BYOD |
| It protects applications from threats and vulnerabilities | > Application security |
| It is the use of various services, such as software development platforms, servers, storage and software, over the internet, often referred to as the "cloud." | > Cloud Computing |
| It determines the best path from the available paths for the transmission of the packet. | > router |
| It is a logical subdivision of an IP network. | > subnet |
| It identifies communication partners, resource availability, and synchronizes communication. | > Application Layer |
| CEP stands for: | > Certificate Enrollment Process |
| It provides a set of tools to secure data, authenticate users, and protect against data loss or theft. | > PKI |
| It is typically a company that provides an auxiliary product not supplied by the primary manufacturer to the end user | > Third party |
| A mechanism for keeping a door, lid, etc., fastened, typically operated only by a key of a form. | > Locks |
| It is the acknowledgement of risks and the active process of reducing or eliminating those risks. | > Risk Awareness |
| They could be suppliers, customers, agents, resellers, vendors, etc. | > Business Partners |
| The loss of the electrical power network supply to an end user. | > Power fluctuations and failures |
| These are related to medicine, vaccines and medical devices. | > Adverse events |
| The effort made by end users or system administrators in recovering and restoring a computer from a problem that has made it inaccessible | > Incident Recovery |
| The following incident report can be used by except | > a person without any idea what happen |
| Setting up a domain of another person or company with the sole intention of selling it to them later at a premium price. | > Cybersquatting |
| Hacking, threats, and blackmailing towards a business or person. | > Cyber terrorism |
| This allows recovery teams to begin recovery even if key IT personnel are unavailable | > Provide the step-by-step protocols |
| By having a business continuity management policy in place, recovery personnel will understand their roles for both internal and external emergency communication | > Prioritize emergency communications |
| It is a set of rules designed to enhance computer security by encouraging users to employ strong passwords and use them properly. | > Password policy |
| It is a process that guarantees that the contents of a message have not been altered in transit. | > Digital Signature |
| It typically contains a link to a Web site that the spimmer is trying to market. | > Spim |
| It imitates (something) while exaggerating its characteristic features for comic effect | > Spoofing |
| It is a Trojan that is designed to gather information from a system. | > Password stealer |
| It refers to any method by which authorized and unauthorized users can get around normal security measures and gain high level user access (aka root access) on a computer system, network, or software application. | > Backdoor Attacks |
| It is a single, cumulative package that includes information that is used to address a problem in a software product. | > service pack |
| It is a directory services implementation that provides all sorts of functionality like authentication, group and user management, policy administration and more. | > Active Directory |
| It determines the number of unique new passwords that must be associated with a user account before an old password can be reused. | > Password history |
| It is a verbal or written answer. | > Response |
| The IT department has setup a share point site to be used on the intranet. Security has established the groups and permissions on the site. No one may modify the permissions and all requests for access are centrally managed by the security team. This is a | > Mandatory access control |
| It may try to close all pop-up windows, some may remove all advertising from a publisher's Web site, and still others may help you choose which pop-up windows you want to be closed with block list feature. | > pop-up blocker |
| It is the tool used for dividing a network into smaller parts which are called subnetworks or network segments. | > VLAN Management |
| It is the predecessor to the modern TLS encryption used today. | > SSL |
| In this type of testing, the code is visible to the tester. | > WHITE BOX TESTING |