1/239
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Which of the following is FALSE about rootkits?
a. A rootkit is malware that can hide the presence of other malware.
b. Rootkits continue to be used extensively and their usage has not diminished.
c. Rootkits can be used to hide its own presence.
d. Rootkits cannot be detected by either an OS or common antimalware scanning software.
Rootkits continue to be used extensively and their usage has not diminished.
What is the goal of a buffer overflow attack?
a. To change the address in the buffer to the attacker's malware code
b. To cause the computer to function erratically
c. To steal data stored in RAM
d. To link to an existing rootkit
To change the address in the buffer to the attacker's malware code
Which area of computer memory is dynamic memory for the programmer to allocate as necessary?
a. Text
b. Stack
c. Heap
d. Data
Heap
Jan is explaining to his colleague the reasons why a web application infrastructure is a tempting target for attackers. Which of the following is NOT a reason Jan would give?
a. A successful compromise could impact all web users who access the web server.
b. An attack could provide a pathway into the enterprise's network infrastructure.
c. An attack on a web application infrastructure is considered the easiest attack to create.
d. The multiple elements in a web application infrastructure provide for a range of vulnerabilities that can be used as different attack vectors.
An attack on a web application infrastructure is considered the easiest attack to create.
Which of the following is FALSE about a cross-site scripting (XSS) attack?
a. The underlying web application that accepts the malicious code becomes the vehicle to deliver the malicious script to every user's browser when he or she accesses that site.
b. An attacker attempts to execute malicious scripts in the victim's web browser by directly injecting it into the user's web browser.
c. XSS is essentially a client-side code injection attack using a web application.
d. The term cross-site scripting refers to an attack using scripting that originates on one site (the web server) to impact another site (the user's computer).
An attacker attempts to execute malicious scripts in the victim's web browser by directly injecting it into the user's web browser.
Ricardo is reviewing the different types of XSS attacks. Which attack only impacts the user who entered the text on the website?
a. Reflected XSS
b. Persistent XSS
c. Document Object Model XSS
d. Universal XSS
Reflected XSS
What is the goal of a SQL injection attack?
a. To corrupt data in the database
b. To manipulate a NoSQL database
c. To extract data from a database
d. To inject malware that will infect the web browsers of subsequent users
To extract data from a database
Bette is researching how a session hijacking attack could occur. Which of the following would she NOT find as a means for the attack to occur?
a. MITM
b. XSS
c. Guessing the session ID
d. MVFL
MVFL
Which of the following is FALSE about a password spraying attack?
a. It takes one or a small number of commonly used passwords in attempts to break into an account.
b. Because it is spread across many different accounts, it is much less likely to raise any alarms.
c. It is considered as the optimal means for breaking into accounts.
d. It is a type of targeted guessing.
It is considered as the optimal means for breaking into accounts.
Why is credential stuffing effective?
a. Because users repeat their passwords on multiple accounts
b. Because it can circumvent all known password security protections
c. Because it is the fastest known password cracking attack
d. Because it is the oldest and most reliable attack on passwords
Because users repeat their passwords on multiple accounts
What is the goal of a directory traversal attack?
a. It has no goal other than to silently look through files stored on a file server.
b. Its goal is to move from the root directory to other restricted directories.
c. Its goal is to identify a vulnerability in a server or endpoint so that access can be gained into a network.
d. Its goal is to pivot to another server.
Its goal is to move from the root directory to other restricted directories.
What is pretexting?
a. Sending text messages to selected victims
b. Obtaining private information
c. Preparing to enter a network through a RCE vulnerability
d. Moving laterally before entering a vulnerable endpoint
Obtaining private information
Which type of OS is found on an embedded system?
a. RSTS
b. SoC
c. RTOS
d. XRXS
RTOS
Aiko has been asked by her friend if she should download and install an app that allows her to circumvent the built-in limitations on her Android smartphone. What is this called?
a. Jailbreaking
b. Side-caring
c. Rooting
d. Pivoting
Rooting
Aiya wants a new notebook computer. She has asked a technician about a model that has USB OTG. Which of the following would the technician NOT tell Aiya about USB OTG?
a. A device connected via USB OTG can function as a peripheral for external media access.
b. A device connected via USB OTG can function as a host.
c. Connecting a mobile device to an infected computer using USB OTG could allow malware to be sent to that device.
d. USB OTG is only available for connecting Android devices to a subnotebook.
USB OTG is only available for connecting Android devices to a subnotebook.
The organization for which Cho works has just purchased a manufacturing plant that has many machines using Modbus. Cho has been asked to research Modbus. Which of the following will Cho NOT find regarding Modbus?
a. Many SCADA systems use Modbus.
b. The original version of Modbus used serial ports.
c. A later variation to Modbus incorporated the TCP/IP protocol.
d. Modbus is robust security.
Modbus is robust security.
What is the network used in vehicles for communications?
a. CAN
b. ECU
c. EDU
d. M-BUS
CAN
Which of the following is NOT a security constraint for embedded systems and specialized devices?
a. Power
b. Compute
c. Cost
d. Patches
Patches
Which of the following is the greatest asset but also a security vulnerability of a mobile device?
a. Low cost
b. Portability
c. Cameras
d. Small screen
Portability
What is geo-tagging?
a. Restricting where an app functions based on its location.
b. Adding geographical identification data to media.
c. Tracking a victim who is wearing a GPS-enabled wearable device.
d. Using the GPS feature of a smartphone.
Adding geographical identification data to media.
Abby has received a request for a data set of actual data for testing a new app that is being developed. She does not want the sensitive elements of the data to be exposed. What technology should she use?
a. Masking
b. Tokening
c. Data Object Obfuscation (DOO)
d. PII Hiding
Masking
Braden has been asked to serve as the individual to whom day-to-day actions have been assigned by the owner. What role is Braden taking?
a. Data custodian/steward
b. Data privacy officer
c. Data controller
d. Data processor
Data custodian/steward
Cora is researching access control schemes. Which scheme will Cora find is the least restrictive?
a. Role-Based Access Control
b. MAC
c. Rule-Based Access Control
d. DAC
DAC
Mia is teaching a new intern about permissions. The intern asks about is a set of permissions attached to an object. Which of these will Mia tell her are permissions attached to an object?
a. ACL
b. SRE
c. Object modifier
d. Entity attribute (EnATT)
ACL
Gabe needs a mechanism that will provide both filesystem security and network security. Which of these will he choose?
a. DBAs
b. DAPs
c. HAPs
d. ACLs
ACLs
Will is searching for information on geographic access requirements. What is another name for this technology that Will can search for?
a. Geolocating
b. Geofencing
c. Geotagging
d. Geoidentifying
Geofencing
Rowan is explaining to a colleague that encryption can provide a range of security protections. Which of these would Rowan NOT include in the list of protections?
a. Nonrepudiation
b. Accounting
c. Integrity
d. Confidentiality
Accounting
hich of the following is used to protect IP?
a. BLB
b. ARC
c. XLS
d. DRM
DRM
Which of the following is NOT correct about watermarking?
a. It can be erased if the content is altered.
b. It is invisible.
c. It allows for unauthorized duplications to be traced back to the source.
d. It is used with DRM.
It can be erased if the content is altered
Which of the following allows deidentified material to be retrieved as needed?
a. Data masking
b. Element obfuscation
c. Tokenization
d. Reordering
Tokenization
Which of the following is NOT true about data sovereignty?
a. Data sovereignty is a concept that until recently was less of an issue.
b. Generally, data is subject to the laws of the country in which it is collected or processed.
c. Governments cannot force companies to store data within specific countries.
d. Data sovereignty is the country-specific requirements that apply to data.
Governments cannot force companies to store data within specific countries
Which of the following is NOT covered by DRM?
a. Ebooks
b. PHI
c. Music
d. Computer games
PHI
Which of the following techniques turns paper into dust so that any data contained on the paper is destroyed?
a. Hammering
b. Stoning
c. Pulverizing
d. Pulping
Pulverizing
Which of the following permanently destroys an entire hard drive by eliminating the magnetic field?
a. Wiping
b. Magnetic stripping
c. Degaussing
d. HDD purging
Degaussing
Which of the following is NOT a nontechnical control?
a. Identifying data
b. Data masking
c. Data sovereignty
d. Nondisclosure agreements
Data masking
Which of the following data types results in the highest risk of fines if the data is exposed?
a. Sensitive
b. High risk
c. Medium value
d. Private
High risk
Which of the following involves determining how long data must be kept?
a. Data retention
b. Data storage
c. Data collection
d. Data analysis
Data retention
Which of the following is NOT a basic principle when considering the retention of data?
a. Always retain data for six months after it is no longer used.
b. Organizations must be able to justify their decisions.
c. Periodic reviews of the data being held are necessary.
d. A policy must be in place.
Always retain data for six months after it is no longer used
Which of the following is a principle that data collected for one specified purpose should not be used for a new purpose?
a. Data amalgamation
b. Reuse restriction
c. Data specificity
d. Purpose limitation
Purpose limitation
Which of the following is NOT a user concern regarding the risks associated with the usage of their private data?
a. The inability to retrieve stolen data
b. Individual inconveniences
c. Associations with groups
d. Statistical inferences
The inability to retrieve stolen data
Which of the following threats would be classified as the actions of a hactivist?
a. Compliance threat
b. Internal threat
c. Environmental threat
d. External threat
External threat
Which of these is NOT a formal and documented response to risk?
a. Mitigation
b. Transference
c. Resistance
d. Avoidance
Resistance
Which of the following is NOT a threat classification category?
a. Compliance
b. Financial
c. Tactical
d. Strategic
Tactical
In which of the following threat classifications would a power blackout be classified?
a. Operational
b. Managerial
c. Technical
d. Strategic
Operational
Which of the following is a systematic evaluation of the effectiveness of the controls as compared to a state of established criteria?
a. Comparison
b. Evaluation
c. Assessment
d. Audit
Audit
Which of the following frameworks focuses on the management and measurement of risk?
a. Prescriptive frameworks
b. Descriptive frameworks
c. Risk-based frameworks
d. Assessment frameworks
Risk-based frameworks
What does a work product retention policy address?
a. How long a document of work must be retained before it can be destroyed
b. What the approved methods are for storing a document
c. Who owns material produced by an employee
d. Where a document can be stored
Who owns material produced by an employee
Which of the following is NOT covered by an AUP?
a. Vendors
b. Competitors
c. Visitors
d. Contractors
Competitors
Which of the following is a step-by-step implementation of a policy?
a. Standard
b. Procedure
c. Guideline
d. Rule
Procedure
Which of the following approaches to risk calculation typically assigns a numeric value (1-10) or label (High, Medium, or Low) to represent a risk?
a. Quantitative risk calculation
b. Qualitative risk calculation
c. Rule-based risk calculation
d. Policy-based risk calculation
Qualitative risk calculation
Which of the following is a list of potential threats and associated risks?
a. Risk assessment
b. Risk matrix
c. Risk register
d. Risk portfolio
Risk register
Giovanni is completing a report on risks. Which risk option would he use to classify the action that the organization has decided not to construct a new a data center because it would be located in an earthquake zone?
a. Transference
b. Avoidance
c. Rejection
d. Prevention
Avoidance
Which of the following control categories includes conducting workshops to help users resist phishing attacks?
a. Managerial
b. Operational
c. Technical
d. Administrative
Operational
Emiliano needs to determine the expected monetary loss every time a risk occurs. Which formula will he use?
a. AV
b. SLE
c. ARO
d. ALE
SLE
Simona needs to research a control that attempts to discourage security violations before they occur. Which control will she research?
a. Deterrent control
b. Preventative control
c. Detective control
d. Corrective control
Deterrent control
Which of the following is NOT correct about supply chain infections?
a. They can be mitigated by VDD.
b. Supply chain assessment can reduce the risk.
c. They only involve software.
d. A supply chain is often global and more difficult to monitor.
They only involve software
What identifies business processes and functions and then quantifies the impact a loss of these functions may have on business operations?
a. BIA
b. VDR
c. RBP
d. AUP
BIA
Which of the following is NOT a category of risk?
a. Internal and external
b. Legacy systems
c. Public
d. Multiparty
Public
Which threat classification affects the long-term goals of the organization?
a. Managerial
b. Financial
c. Compliance
d. Strategic
Strategic
Which of the following is NOT used in a cyber systems assessment?
a. SOAR analysis
b. Analytical testing
c. Vulnerability assessment
d. Penetration testing
SOAR analysis
Which of the following is NOT a reason why computer forensics is important?
a. Amount of digital evidence
b. Increased scrutiny by the legal profession
c. Higher level of computer skill by criminals
d. Federal laws that mandate all attacks be examined using forensics
Federal laws that mandate all attacks be examined using forensics.
What is the name of a device that prevents writing to a hard drive?
a. Drive blocker
b. Write blocker
c. Sector restrictor
d. Device blocker
Write blocker
What type of cameras should NOT be used in a forensics investigation?
a. Digital still camera
b. Video camera
c. Still camera
d. HD camera
Digital still camera
Alvaro has been asked to acquire tape to secure evidence bags that cannot be removed and reapplied without leaving visual evidence. What type of tape should he use?
a. Tamper-evident
b. Tamper-resistant
c. Tamper-impervious
d. Tamper-controlled
Tamper-evident
Which of the following is NOT a name for a unique digital fingerprint of a set of data?
a. Hash
b. Digest
c. Message digest
d. Certificate
Certificate
Which imaging utility can generate a physical image copy?
a. dd
b. dr
c. dt
d. de
dd
Which of the following is NOT a reason for bandwidth monitoring?
a. To identify cyber incident
b. To troubleshoot network performance
c. To monitor bandwidth agreements
d. To find application buffer overflows
To find application buffer overflows
Which of the following is NOT a reason for a traffic spike?
a. Mail server problems
b. Software updates
c. Remote external backups
d. Processor consumption
Processor consumption
Which of the following is NOT a helpful question in determining the cause of a traffic spike?
a. Do the spikes appear at the same time on the same day?
b. Do other monitoring points on the network match these patterns?
c. Do the spikes occur during business hours or at other times?
d. Is the traffic using all common protocols?
Is the traffic using all common protocols?
Which of the following is false about traffic spikes?
a. Using traffic spikes as a symptom of a cyber incident is considered to be easy and straightforward.
b. A malware's spike can become camouflaged among normal spikes.
c. Malware can be programmed to perform an event that causes a traffic spike on a regular interval.
d. Normal traffic spikes are not uncommon.
Using traffic spikes as a symptom of a cyber incident is considered to be easy and straightforward.
Aika wants to monitor bandwidth consumption to determine if there has been a cyber incident. What will be her first step?
a. Identify an open port on the router.
b. Install a packet tracker on the network.
c. Receive permission from her Internet Service Provider (ISP).
d. Establish a baseline of normal bandwidth utilization.
Establish a baseline of normal bandwidth utilization.
Which of the following is false about beaconing?
a. Beaconing occurs when infected devices attempt to contact the threat actor's external C&C server.
b. Beaconing is a three-way communication process.
c. Beaconing is used to receive updated or new instructions from a C&C server.
d. Data exfiltration is accomplished through beaconing.
Beaconing is a three-way communication process.
Which of the following is NOT a type of attack that can be generated through a botnet?
a. Spamming
b. Spreading malware
c. Buffer overflows
d. Manipulating online polls
Buffer overflows
Etsu is reviewing log files and discovers that data has been stolen and sent out from the network. In her report, what does she call this?
a. Exfiltration
b. Infiltration
c. Gathering
d. Sweeping
Exfiltration
Why would a threat actor NOT use BitTorrent for data exfiltration?
a. BitTorrent has never been used for data exfiltration and thus is untested.
b. BitTorrent is not popular and would be difficult for the threat actors to find clients.
c. BitTorrent is considered too slow for file transfers.
d. The BitTorrent protocol can be easily identified.
The BitTorrent protocol can be easily identified.
Which of the following is NOT true about a P2P C&C?
a. It can mask irregular peer-to-peer communications but not data exfiltration through beaconing.
b. A single compromised computer acts as an internal C&C device.
c. It uses an internal mesh network.
d. A P2P C&C uses common protocols.
It can mask irregular peer-to-peer communications but not data exfiltration through beaconing.
If an attacker wants to learn which services are running on a server, which of the following would he use?
a. Port scan
b. Sweep scan
c. Ping sweep
d. IP sweep
Port scan
Which of the following about new account creation is false?
a. Malware can often attempt to compromise a user application database by creating a new account.
b. New account creation can only be used for a threat actor to log in to the application.
c. New account creation should be immediately investigated.
d. Some applications allow logging in to an application to only be performed by the same Windows user who created the database.
New account creation can only be used for a threat actor to log in to the application.
Which of the following is NOT correct about tcpdump?
a. Various forks are available for Windows computers.
b. It operates on UNIX and Linux OS.
c. It only displays TCP/IP packets being transmitted.
d. It is a command-line packet analyzer.
It only displays TCP/IP packets being transmitted.
Which of the following is the best way to perform forensics on a VM?
a. Suspend the VM and resume it later under forensic analysis so that the forensics investigator can use normal procedures to analyze the VM.
b. Take a snapshot of the state of the hard disk so that it is preserved and any changes to the disk are stored in a separate file.
c. Load the VM into a virtual container box (VCB) and use regular forensic tools.
d. It is not recommended that forensics be performed on a VM due to its volatile nature.
Take a snapshot of the state of the hard disk so that it is preserved and any changes to the disk are stored in a seperate file.
What is the act of violating an explicit or implied security policy that may or may not be successful?
a. Cyber breach
b. Cyber incident
c. Security event
d. Adverse security event
Cyber incident
Adamo has been asked to create a new cyber incident response plan. What will be the final phase in the plan?
a. Reporting
b. Eradication
c. Recovery
d. Post-Incident
Post-Incident
Rico is developing a list of personnel who may be asked to serve on a cyber incident response team. Who will have the responsibility of helping the team to focus on minimizing damage and recovering quickly from a cyber incident?
a. Associate director
b. Coordinator
c. Lead investigator
d. Team leader
Team leader
Viola is examining data that was compromised during a recent attack. Into which category would a password number be classified?
a. PII
b. PHI
c. SPI
d. PUI
PII
Which of the following is NOT an example of intellectual property?
a. Trademark
b. Brand image
c. Copyright
d. Patent
Brand image
Why is financial information data considered to have a high value?
a. The loss of accounting data prevents an organization from providing stakeholders an accurate picture of its financial health.
b. Federal laws prohibit backing up corporate accounting data, so the loss cannot be replaced.
c. Corporate accounting data has a high value only if it is part of a merger and acquisition.
d. Accounting data is very detailed and would require a significant effort to restore it.
The loss of accounting data prevents an organization from providing stakeholders an accurate picture of its financial health.
What is the first step in determining the detection and analysis phase of incident response?
a. Deciding how many systems were impacted
b. Determining who launched the attack
c. Deciding if what occurred was a cybersecurity incident
d. Examining the type of data that was compromised
Deciding if what occurred was a cybersecurity incident.
Which of the following scopes of impact describes the length of time needed for IT systems to return to their normal functions?
a. Downtime
b. Recovery time
c. Response time
d. Recapture time
Recovery time
Kristin is reviewing the impact of a recent attack and found that it only caused a seldom-used test server to be taken offline for short period of time. She has decided that this incident does not deserve a high priority ranking. What scope of impact has she used in making this determination?
a. Network importance measure (NIM)
b. System evaluation
c. System process criticality
d. Structural impact
System process criticality
What is the best way for an organization to limit adverse public reactions to a cyber incident?
a. By keeping the news of a cyber incident secret
b. By controlling the conversation
c. By communicating only with stakeholders
d. By responding defensively
By controlling the conversation
Which of the following is NOT a reason for communications in a cyber incident?
a. To limit adverse reactions
b. To allow for unplanned release of information
c. To satisfy state legislative mandates
d. To meet federal regulatory requirements
To allow for unplanned release of information
Which of the following is false regarding state legislative mandates about communication in a cyber incident?
a. Only California has a state security breach notification law.
b. No two state laws are identical.
c. Some states have a broader definition of personal information.
d. Providing notice to the State Attorney General is required in some states.
Only California has a state security breach notification law.
Pat is researching requirements for communicating with affected parties in a cyber incident. What requirement would Pat find that is in place in the European Union (EU)?
a. PIPEDA
b. GDPR
c. PI
d. ICO
GDPR
Isabella has been asked to research HIPAA requirements for her employer. Which of the following is false regarding HIPAA?
a. Healthcare enterprises must guard protected healthcare information.
b. HIPAA only applies to information in electronic format.
c. HIPAA includes any third-party business associate that handles protected healthcare information.
d. Healthcare enterprises must implement policies and procedures to safeguard information.
HIPAA only applies to information in electronic format.
For internal communications, which two categories are often used?
a. Senior-level and junior-level
b. Technical and management
c. Security and networking
d. Communication and cyber
Technical and management
Kaitlyn is creating an incident response plan. Who should first be notified in the event of a cyber incident?
a. Cyber incident response team
b. CEO
c. Law enforcement
d. Local media
Cyber incident response team
Which of the following is not a reason for contacting law enforcement agencies in the event of a cyber incident?
a. They can work with foreign counterparts to stop organized cybercrime.
b. They have many resources and experience.
c. Identifying threat actors often leads to no arrests or convictions.
d. Companies providing information can assist in intelligence sharing efforts.
Identifying threat actors often leads to no arrests or convictions.
Eva is researching which law enforcement agency to contact in the event of different types of cyber incidents. Which law enforcement agency should be contacted no matter the type of incident?
a. CIA
b. NSA
c. FBI
d. Secret Service
FBI
Which of the following is NOT a communications best practice strategy?
a. Contact local news media before the word leaks out.
b. Use a secure method of communication.
c. Be transparent but be careful.
d. Provide a context.
Contact local news media before the word leaks out.
Anabelle needs to eradicate malware from a hard drive. Which should she NOT do?
a. Delete the files from the hard drive by using the Quick Format option.
b. Overwrite the data using sanitization.
c. Use secure disposal as a last resort.
d. Use the Schneier sanitation method.
Delete the files from the hard drive by using the Quick Format option.