1/146
Quiz 1: 1.0 Security concepts: Sec 1.1 – 1.3, Quiz 2: 2.0 Threats, Vulnerabilities, and Mitigations: Sec 2.1 – 2.3 - 3.0 Cryptographic Solutions: Sec 3.1 – 3.5
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Security operations center (SOC)
The location where security professionals monitor and protect critical information assets in an organization.
Development and operations (DevOps)
A combination of software development and systems operations and refers to the practice of integrating one discipline with the other.
DevSecOps
A combination of software development, security operations, and systems operations and refers to the practice of integrating each discipline with the others.
Computer incident response team (CIRT)/computer security incident response team (CSIRT)/computer emergency response team (CERT)
Team with responsibility for incident response. The CSIRT must have expertise across a number of business domains (IT, HR, legal, and marketing, for instance).
computer incident response team (CIRT)
team with responsibility for incident response. The CIRT must have expertise across a number of business domains (IT, HR, legal, and marketing, for instance).
You are the Chief Information Security Officer (CISO) at a large corporation. You have been tasked with implementing a new security control to protect sensitive customer data.
The control must be able to automatically detect and prevent unauthorized access to the data.
Which type of control should you implement?
Technical control
You are the head of the cybersecurity team at a large corporation. You notice an increase in network traffic that appears to be legitimate but is causing a slowdown in your systems.
Upon further inspection, you find that the traffic patterns vary each time, making it difficult to distinguish from normal traffic.
What type of security challenge are you MOST likely facing?
Sophisticated attack
You are the Chief Information Security Officer (CISO) at a large corporation. Your company is expanding rapidly and the complexity of managing security across different business functions is increasing.
You need a dedicated team to monitor and protect critical information assets across the organization.
Which of the following would be the MOST effective solution?
Establishing a Security Operations Center (SOC)
Which of the following security challenges refers to the rapid and broad spread of an attack, often affecting a large number of computers in a relatively short amount of time?
Attack scale and velocity
Which of the following is a method of implementing security controls?
Managerial controls
Your computer system is a participant in an asymmetric cryptography system. You've created a message to send to another user. Before transmission, you hash the message and encrypt the hash using your private key. You then attach this encrypted hash to your message as a digital signature before sending it to the other user.
In this example, which protection does the hashing activity provide?
Integrity
You are the Chief Information Security Officer (CISO) at a tech company. Your company is facing issues with silos between the development and operations teams, leading to inefficiencies and security vulnerabilities.
Which approach should you adopt to encourage collaboration and integrate security considerations at every stage of software development and deployment?
Adopting a Development and Operations (DevOps) approach
A user copies files from her desktop computer to a USB flash device and puts the device into her pocket.
Which of the following security risks is MOST pressing?
Confidentiality
A large multinational corporation has recently experienced a significant data breach. The breach was detected by an external cybersecurity firm, and the corporation's IT department was unable to prevent or detect the breach in its early stages.
The CEO wants to ensure that such a breach does not happen again and is considering several options to enhance the company's security posture.
Which of the following options would be the MOST effective in preventing and detecting future data breaches?
Implementing a dedicated Computer Incident Response Team (CIRT).
Which of the following are often identified as the three main goals of security? (Select three.)
Integrity, Confidentiality, Availability
Security Control
A technology or procedure put in place to mitigate vulnerabilities and risk and to ensure the confidentiality, integrity, and availability (CIA) of information.
Managerial
A category of security control that provides oversight of information systems.
Operational
A category of security control that is implemented by people.
Technical
A category of security control that is implemented as a system.
Physical
A category of security control that is implemented by hardware used to deter or detect, such as alarms, gateways, locks, lighting, and security cameras.
Preventive
A type of security control that acts before an incident to eliminate or reduce the likelihood that an attack can succeed.
Access control lists (ACLs)
The collection of access control entries (ACEs) that determines which subjects (user accounts, host IP addresses, and so on) are allowed or denied access to the object and the privileges given (read-only, read/write, and so on).
Detective
A type of security control that acts during an incident to identify or record that it is happening.
Corrective
A type of security control that acts after an incident to eliminate or minimize its impact.
Directive
A type of control that enforces a rule of behavior through a policy or contract.
Deterrent
A type of security control that discourages intrusion attempts.
Compensating
A security measure that takes on risk mitigation when a primary control fails or cannot completely meet expectations.
Chief Information Officer (CIO)
A company officer with the primary responsibility of managing information technology assets and procedures.
Chief Technology Officer (CTO)
A company officer with the primary role of making effective use of new and emerging computing platforms and innovations.
Chief Security Officer
Typically, the job title of the person with overall responsibility for information assurance and systems security.
Informations Systems Security Officer (ISSO)`
Organizational role with technical responsibilities for implementation of security policies, frameworks, and controls.
A company finds that employees are accessing streaming websites that are not being monitored for malware or viruses.
Which type of control can the network administrator implement to protect the system and keep the employees from viewing unapproved sites?
Technical
Which of the following is an example of a preventative control type?
An advanced network appliance
After a recent server outage, the company discovered that an employee accidentally unplugged the power cable from the server while grabbing some office supplies from the nearby shelf.
What security control did the company lack that led to the server outage?
Physical
An acceptable use policy requires the system to encrypt confidential information while in transit. All employees must use secure email when exchanging proprietary information with external vendors.
Which of the following describes this type of acceptable use policy?
Operational
Which type of control makes use of policies, DRPs, and BCPs?
Managerial
The security operations manager of a multinational corporation focuses on enhancing directive operational controls.
Which of the following should the manager implement?
User awareness and training programs.
Which type of control is used to discourage malicious actors from attempting to breach a network?
Deterrent
The chief security officer (CSO) at a financial organization wants to implement additional detective security controls.
Which of the following would BEST represent this type of control?
Installation of surveillance camera.
A company moved its office supplies to another room and instituted a new security system for entry. The company implemented this after a recent server outage.
What category of security control BEST describes the function of this recent implementation?
Corrective
Which of the following BEST describes compensating controls?
Partial control solution that is implemented when a control cannot fully meet a requirement.
The IT department at a large corporation noticed an unfamiliar software application running on its network. Upon investigation, they discovered that a team in the marketing department started using a new cloud-based project management tool to improve their workflow efficiency.
The team did not consult with the IT department before implementing this tool.
In the context of cybersecurity threats, what does this situation BEST exemplify?
Shadow IT
A multinational corporation recently fell victim to a series of cyberattacks, disrupting services and leading to significant financial losses. After an investigation, the corporation found that these attacks were part of a systematic campaign to undermine the corporation's market position.
The highly sophisticated attacks suggest the involvement of a well-resourced entity with specific strategic objectives.
Which of the following motivations BEST describes this scenario?
Political
Which type of threat actor is MOST likely to engage in cyber espionage with strategic or political motivations?
Nation-state
The IT manager in your organization proposes taking steps to deflect a potential threat actor. The proposal includes the following:
Create and follow onboarding and off-boarding procedures.
Employ the principal of least privilege.
Have appropriate physical security controls in place.
Which type of threat actor do these steps guard against?
Insider
A prominent multinational corporation has experienced an unexpected spike in unauthorized network traffic aimed at its web servers. Upon investigation, the corporation discovered that the goal of this traffic was to disrupt its online services rather than gain unauthorized access or steal data.
The attack started shortly after the corporation made a controversial policy decision that sparked a public backlash.
Which type of threat actor is MOST likely responsible?
Hacktivist
In which phase of an attack does the attacker gather information about the target?
Reconnaissance
Reconnaissance
process of gathering information about an organization, including system hardware information, network configuration, and individual user information.
Breach
penetration of system defenses. Breaches are achieved using the information gathered during reconnaissance.
Escalating privileges
one of the primary objectives of an attacker, which can be achieved by configuring additional (escalated) rights to do more than breach the system.
Staging
preparing a computer to perform additional tasks in the attack, such as installing software designed to attack other systems.
Exploit
take advantage of known vulnerabilities in software and systems. Types of exploitation include stealing information, denying services, crashing systems, and modifying information.
As a cybersecurity analyst, you are tasked with reducing the supply chain attack surface in your organization.
Which of the following areas should you focus on to MOST effectively mitigate this risk?
Vendor management
A group of hackers has been monitoring recent orders from a company involving new laptops and Universal Serial Bus (USB) thumb drives. The group infiltrated the shipping company and added malicious USB thumb drives to the order. The target company received the order without any concerns.
What vectors made this attack successful?
Supply chain, Removable media
CloudSecure is facing a cybersecurity challenge where some of its critical software applications are no longer supported by vendors, making them vulnerable to potential exploits. The IT team is exploring various strategies to mitigate the risk posed by these unsupported apps.
What is the MOST effective approach to enhance the security posture?
Isolating the unsupported apps from other systems to reduce the attack surface.
An attack that targets senior executives and high-profile victims is referred to as what?
Whaling
Which of the following is a passive computer attack technique in which an attacker anticipates or observes the websites an organization uses often and infects them with malware?
Watering hole
A representative at a company reports receiving numerous unsolicited phone calls seeking banking information for a credit report.
Which social engineering variant is the finance director experiencing?
Vishing
What is the term for a phishing attack conducted through a voice channel, such as a phone call?
Vishing
Employees at CloudCom receive a suspicious email claiming to be from "CloudCom Support," informing employees that their passwords need to be reset urgently due to a security breach. The email includes a link to a login page that looks identical to CloudCom's official site.
What type of social engineering attack does this scenario exemplify?
Typosquatting
The cybersecurity manager of a large organization is investigating a recent security breach that occurred during office hours. Investigatory research shows that the suspect convinced the janitor to let them inside the building because they had forgotten their badge at home.
Once inside, the suspect pulled the fire alarm and accessed the building's network room amongst the chaos. The intruder then attached a monitoring device to a network port before escaping unnoticed.
Which of the following is the social engineering technique the threat actor employed in this scenario?
Pretexting
An employee receives an email from an unknown sender claiming to be from the IT department.
The email states that there is a login issue on the network and that the user needs to run the file to resolve the problem. The executable file prompts the user to input a network password, which the threat actor records.
What social engineering technique is the threat actor using in this scenario?
Phishing
Which of the following is an example of a Vishing social engineering attack?
A call from a threat actor posing as a remote sales representative to obtain the login credentials to a remote access server from the help desk.
You are a cybersecurity analyst at a large corporation. You notice that a particular employee has been receiving emails from an unknown sender who claims to be a new colleague from a different department.
The sender has been engaging in friendly conversation, asking about the employee's role, and subtly inquiring about certain company processes. Recently, the sender asked the employee to open an attachment that supposedly contains a funny meme.
What phase of the social engineering process does this scenario represent and what should be your immediate action?
Exploitation phase - Isolate the employee's system and conduct a thorough security scan.