1/17
1ST MODULE
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What statement describes the relationship between cyberattacks and cyber exlpoits
Cyberattacks are high level malicious actions aimed at achieving specific objectives, while cyber exploits are the techniques to find and take advantages of vulnerabilities to carry out these attacks.
What statement describes the scope of physical security
Physical security involves protecting building sites and equipment from various threats, including theft, vandalism, natural disasters, and accidental damage.
what are three recommended best practices for safeguarding hosts against malware?
-Developing and enforcing a patch management policy
-Implementing strong password policies and changing default passwords.
-Removing unused windows components, protocols, services, and applications.
What three security measures would effectively deal with access- related attacks in a network environment
-Use static configuration of switch ports and disabling port mode auto negotiation.
-Disable native VLANs to reduce security risks
-Implement policies to prevent rogue wireless access points and unauthorized end-host systems from connecting to the network
A state sponsored hacker has developed a malware framework and carried out cyberattacks on industrial automation and control systems (IACS) and SCADA devices. What is the primary goal of the state-sponsored hacker?
To gain persistent access and sabotage mission critical operations of liquefied natural gas and electric power organizations
Energy sector
This sector involves the generation, transmission, and distribution of electricity, oil, and natural gas, which are crucial for the operation of nearly all other critical infrastructure sectors
Healthcare and Public Health sector
This sector ensures the provision of medical care, emergency services, and the safeguarding of public health.
Water and wastewater systems sector
This sector is responsible for the infrastructure that supplies clean drinking water and safely removes and treats wastewater.
Communications sector
This sector encompasses the infrastructure that supports the communication networks, including satellites, telephone, and internet services.
Transportation system sector
This sector provides essential services that enable the movement of goods, people, and services, including aviation, rail, highway, maritime, and public transit systems.
To strengthen national critical infrastructure against cyber threats, countries have established dedicated cybersecurity agencies. Which strategy would most effectively support the establishment of dedicated cybersecurty agencies.
Promote collaboration between public agencies, private sector operators, and international partners
NovaChem industries is expanding its industrial operations into three new international markets, to align its cybersecurity practices with global expectations, the company security leadership wants to adopt a framework that will ensure consistency across sites while meeting diverse regulatory expectation, the cybersecurity manager proposes selecting a foundational international standard that will provide broad recognition and interoperability across various countries, while still allowing room to adapt to local requirements. Which action best supports novachem industries goal of building a globally recognized and adaptable cybersecurity program
Adopt ISO/IEC 27001 to establish an internationally accepted information security management system
When an organization is subject to multiple cybersecurity or privacy regulations that address the same requirement, which approach ensures the best comprehensive compliance?
Comply with the strictest requirement among the applicable regulations.
What are three common vulnerabilities found in industrial automation and control systems networks and devices.
Legacy systems running unpatched operating systems
Fragile TCP/IP stack and weak authentication mechanisms
Unauthorized usage of HMI systems for personal internet activities.
What is a significant risk associated with vulnerabilites in connected IACS devices
Manipulation, interruption, or disabling of vital processes, resulting in injury or death
Which three examples represnet logical network access control measures for protecting the edge of an IIoT network?
IEEE 802.1X Authentication
Access Control Lists
Firewalls
What three data types are considered traditional data, typically generated and maintained by organizations
Transactional data
Intellectual property
Financial data
What is a primary security concern for industrial automation and control systems when integrating with IT networks
Availability and integrity of IACS applications due to the high cost of downtime.