1/77
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
According to the lesson, what was Eligible Receiver
Eligible Receiver was a 1997 internal exercise initiated by the DoD utilizing a "red team" of hackers from the NSA who only were allowed to use publicly available computer equipment and software.
There are four basic means by which compromising emanations can be propagated. They are electromagnetic radiation, conduction, modulation od an intended signal, and which of the following?
Acoustics (sound) is the fourth method. Just as vibrations cause sound waves, sound waves can also cause vibrations.
The lesson stated that the Office of Tailored Access Operations (TAO) is a cyber-warfare intelligence-gathering unit of the NSA. It has been active since at least 1998 and identifies, monitors, infiltrates and gathers intelligence on computer systems being used by entities foreign to the U.S.
True
In order to defeat the problem of compromising emanations, the United States Government established the Aurora program. Begun in the mid 1950's this program focuses on evaluating and screening companies and equipment to ensure that electromagnetic radiation from information handling devices are eliminated or controlled.
False. The name of the program is TEMPEST.
In the defense-in-depth strategy that was emphasized in the lesson, which of the following was the innermost layer of defense?
Data defenses are the innermost layer of defense. It is the data you are trying to protect so if all other layers fail to protect it, defenses concentrating on the data are the last line of defense.
Active Cyber Defense (ACD) is nothing more than a "fancy" name given to the strategy of defense-in-depth. It was first introduced as a marketing strategy by Network Data Defenses (NDD) a few years ago but has since been adopted by most of the rest of industry.
False
To implement a security program successfully, an organization must define processes and activities for staff and systems. These policies and procedures define security controls and usage of the controls. An awareness program enhances staff understanding of the security controls. The policies and procedures define and describe all the controls at the other lavers.
This is true and was the description given for the reason for policies, procedures, and awareness in a defense-in-depth strategy
Defense-in-depth seems like a natural and obvious approach to security. In the case of cybersecurity, however, the lesson pointed out that the concept is easy to aspire to in theory but difficult to implement in practice. Which of the following was one of the reasons given in the lesson as to why this is the case?
It only works if all the layers work together as one, so that there is a cohesive view across all attack vectors.
Which layer in a defense-in-depth strategy encompasses every point at which the internal network connects to external networks and hosts?
This is the description of Perimeter Defenses provided in the lesson. Don't get it mixed up with Network Defenses which are focused on the internal network.
The famous SYN flooding attack takes advantage of the 3-way handshake which is part of which protocol?
The three-way handshake that is part of the SYN Flooding attack is part of the TCP protocol.
The Smurf attack is a distributed denial-of-service attack in which large numbers of Internet Control Message protocol (IMP) packets with the intended victim's spoofed source IP are broadcast to a computer network using an IP broadcast address. If a number of machines on the network that receive and respond to these packets is very large, the victim's computer will be flooded with traffic. This can slow down the victim's computer to the point where it becomes impossible to work on.
This is true and is the description of the Smurf attack provided in the lesson.
Which of the following was described in the lesson as "the world's foremost and widely-used network protocol analyzer? It lets you see what's happening on your network at a microscopic level and is the de facto standard across many commercial and non-profit enterprises, government agencies, and educational institutions
Wireshark
Computer Network Attack (CA) entails the scanning and exploiting of computer systems and networks. Conducting this type of activity on systems you don't own or have the permission to assess is illegal.
This was the definition of Computer Network Attack that was provided in the lesson.
Which of the following tools has been described as the world's most used penetration testing framework?
Metasploit
In the model of Defense-in-depth that the lesson concentrated on, what is the outermost layer of security?
Polices, procedures, and awareness
Defense-in-depth is not a product, like a firewall. Instead, it is a security architecture that calls for the network to be aware and self-protective.
True
Which of the following was offered in the lesson as a reason why defense-in-depth strategies can fail?
A, B, and C but not D. Changes in technology, flaws in design, abuse by trusted insiders
To implement a security program successfully, an organization must define processes and activities for staff and systems. These policies and procedures define security controls and usage of the controls. An awareness program enhances staff understanding of the security controls. The policies and procedures define and describe all the controls at the other layers
True
Which of the following is a "data-vacuuming" malware that targeted a number of Middle Eastern countries including Israel and Iran?
Flame
What was the name given to a series of coordinated attacks on American computer systems in 2005 but which had been ongoing for at least 3 years?
The attacks were labeled as Chinese in origin, although their precise nature, e.g. state-sponsored espionage, corporate espionage, or random hacker attacks, and their real identities remain unknown.
Titan Rain
Stuxnet specifically targeted PLCs which allow the automation of electromechanical processes such as those used to control machinery on factory assembly lines. In this case, it targeted the PLCs used by centrifuges for separating nuclear material.
True
How does a Fragmentation attack work?
A and C are descriptions of fragmentation attacks but not B.
UDP and IMP fragmentation attacks send fraudulent packets that are larger than the network's MTU
TCP fragmentation attack sends packets with overlapping fragmentations which the recipient cannot process.
How does the famous SYN attack that utilizes the three-way handshake work? In other words. what does the attack do in order to conduct the denial of service attack?
A SYN packet is sent to the target with a bogus "from" address. The target sends a response and waits for the final ACK but never receives it.
It continues to wait and if enough other similar packets are sent the target gets "tied up" waiting for responses and no more connection requests can be accepted.
The source and destination IP addresses are contained in the header of which of the following protocols?
IP
Which DARPA and OSI layer would you find the TCP and UDP protocols? In other words, the TCP and UDP protocols would be found in what equivalent layers of the OS and DARPA layers?
Transport Layer
What was the name of the tool mentioned in the lesson that performs a DoS attack on a target site by flooding the server with TCP or UDP packets with the intention of disrupting the service of a particular host?
Low Orbit Ion Cannon (LOIC)
of data on a disk is an example of a defense mechanism used in which of the following layers of a defense-in-depth strategy?
Data Defenses
Code Red was a worm with multiple variants that first appeared in July 2001 and ultimately affected nearly 300,000 computers in the U.S. It exploited a hole in Microsoft's IIS Web Servers.
True
What was the name of the "hacking" group from China that emerged after the May 1999 bombing of the Chinese embassy in Belgrade? It's members combined hacking skills with patriotism and nationalism and launched a series of attacks on websites in the U.S
Honker Union
Initially a group calling itself the "Guardians of Peace" (GOP) took credit for the attack on Sony Pictures. Eventually, however, after further investigation it was irrefutably shown that the attack actually was initiated by North Korea.
False
In the TEDx Talk on Cyberwar, the speaker listed 5 differences between cyber threats and conventional threats. One of these was Warning and Decision. What was the issue here?
We get no warning time for a cyber attack and because of the attribution issue a response is often not possible for a possibly considerable period of time.
In which risk response strategy is a portion of the risk responsibility or liability to the organization shifted to another organization?
Risk sharing
In which component of the risk management process are threats to the organization identified?
Assess
Risk management is the process of identifying, examining, measuring, mitigating, or transferring risk. Its main goal is to reduce the probability or impact of an identified risk.
True
Organizational viewpoint refers to the values, beliefs, and norms that influence the behaviors and actions of the senior leader/executives and individual members of an organization.
False
Identification of risk assumptions, risk constraints, Risk tolerance and priorities and trade-offs is part of which component of the risk management process?
Risk framing
The process of estimating the degree of overall harm or loss that could occur as a result of the exploitation of a security vulnerability is known as which of the following?
Impact Assessment or Impact Analysis
A likelihood assessment estimates the probability of a threat conducting some specific activity.
True
What was the term that the lesson used to describe the measure of how much data loss, in hours or days, is acceptable to an organization.
RPO (recovery point objective)
A qualitative assessment typically employs a set of methods, principles, or rules for assessing risk based on the use of numbers.
False
Which approach for calculating risk utilizes a set method, principle or set of rules for assessing risk that uses bins, scales, or represented numbers whose values and meanings are not maintained in other contexts?
Semi-Quantitative Assessment
As described in the lesson, the Risk Management Framework consists of 6 steps. In which step is an initial set of baseline security controls for the information system based on an organizational assessment of risk and local conditions?
Select
In which step of the Risk Management Framework (RMF) do you find the task to implement an informational system disposal strategy, when needed, which executes required actions when a system is removed from service?
Monitor
In which step of the Risk Management Framework (RMF) do you find the task to determine if the risk to organizational operations, organizational assets, individuals, other organizations, or the nation is acceptable?
Authorize
During which step of the Risk Management Framework (RMF) would you find the task to develop a strategy for the continuous monitoring of security control effectiveness and any proposed/actual changes to the information system and its environment of operation?
Select
During which step of the Risk Management Framework (RMF) would you find the task to conduct initial remediation actions on security controls based on the findings and recommendations of the security assessment report and reassess remediated controls), as appropriate?
Assess
The lesson defined the lifecycle of risk management as having three parts which were further defined and discussed. These three parts (not in any particular order) were Risk Mitigation/Response, Risk Analysis; and which of the following?
Risk Assessment
Qualitative and/or Quantitative risk calculations are part of which step of the risk management lifecycle?
Risk Analysis
A Business Impact Analysis (BIA) is the process of developing and distributing a questionnaire to determine the financial impact and operational impact on an organization if its business offices and/or data center facilities are not available for an extended time
True
As discussed in the lesson, which step of the Risk Management Framework (RMF) is the information system assets and individuals allowed to operate based on a determination of the risk to organizational operations and the decision that this risk is acceptable?
Authorize
The authorization package consists of three documents. They are the Security Plan, the Security Assessment Report, and which of the following?
Plan of Action and Milestones
The Risk Management Process consists of 4 components as defined in the lesson. These are Assess, Respond, Monitor, and which of the following?
Frame
Trust is a belief that an entity will behave in a predictable manner in specified circumstances. The entity may be a person, process, object, or any combination of such components.
True
In which component of the risk management process presented in the lesson do you verify that planned risk response measures are implemented and information security requirements derived from/traceable to organizational missions/business functions, federal legislation, directives, regulations, policies, and standards and guidelines are satisfied?
Monitor
Business Continuity Planning (BCP and Disaster Recovery (DR) are terms that are often used synonymously and actually do refer to the same plans. The difference is simply a preference by the individual discussing the topic.
False
The process of understanding the existing system and environment, and identifying risks through analysis of the information/data collected is known as which of the following?
Risk Assessment
Risk Management Framework (RMF) provides a disciplined and structured process that integrates information security and risk management activities into the system development life cycle. It operates primarily at Tier 3 of the 3-tiered approach presented in the lesson.
True
The risk management 3-tiered approach consisted of three levels. Which of the following were the three levels described in the lesson?
Organization,
Mission/Business Processes, Information Systems
When is Risk Avoidance the appropriate risk response?
When the identified risk exceeds the organizational risk tolerance.
The security authorization package documents the results of the security control assessment and provides the authorizing official with essential information needed to make a risk-based decision on whether to authorize operation of an information system.
True
In which step of the Risk Management Framework (RMF) would you find the task of registering the information system with appropriate organizational program/management offices?
Categorize
The Ghost Security Group attacks ISIS online by attempting to shut down accounts or by attacking known jihadi websites rough denial of service (DoS) attacks.
False
What is the name of the group of "hackers" that felt that in the Anonymous-declared war on ISIS, Anonymous was using unsophisticated tactics? The group stated that Anonymous didn't have any counterterrorism experience and they felt that not enough was being done. They thus formed this separate group to take on ISIS
Ghost Security Group
Which of the following were discussed in the lesson as "valid" cyberattacks from a government perspective?
A, B, C, and D, but not E
General Keith Alexander, commander of the U.S. Cyber Command in 2014, pointed out several issues with cyberwar today. Which of the following was an issue he pointed out?
All of the above
Which of the following is the best term used to describe actions and intelligence collection via computer networks that take advantage of data gathered from target or enemy information systems or networks?
Computer Network Exploration (CNE)
What is the term used to describe a computer "hacker" or computer security expert who may sometimes violate laws or typical ethical standards but does not have any malicious intent?
Grey hat hacker
Not in any specific order, the 5 phases of a penetration test are Scanning, Gaining Access, Reconnaissance, Covering Tracks, and which of the following?
Maintaining Access
According to the lesson, the term kill chain was originally used as a military concept related to the structure of an attack. The original cyber kill chain reveals the stages of a cyberattack from early reconnaissance to the goal of data exfiltration.
True
Which of the following is the " of the original "CIA of security"?
Integrity
According to Lara Ballard, special advisor on privacy and technology to the State Department. which of the following is the most valuable type of defense?
Human Intelligence
While there has been much discussion about the vulnerability of industrial control systems in the nation's critical infrastructures, there has actually only been less than a dozen known attacks. This still shows the possibility of attacking our infrastructures and is why DHS has stressed industrial control system security is an increasingly important part of national defense.
False
According to the TED talk on cyberwar, why is the most powerful cyber state also most likely the most vulnerable?
The nation that is the most powerful from a cyber perspective will also have a large reliance on cyber themselves and will therefore also be vulnerable to cyber attacks.
In 2008 malware known as Agent. btz was used in an attack on the Department of Defense. It spread extensively throughout DoD networks. The infection began when an infected USB flash drive was inserted into a U.S. military laptop at a base in the Middle East. As a result the DoD suspended the use of USB drives (i.e. does not allow them) or other external media by service members.
True
Which of the following is the name of the malware identified by DHS deep within the industrial control systems that operate critical infrastructures? It appears to originally only be targeting the theft of information but officials fear it could be modified for sabotage purposes.
Black Energy
As discussed in an article in the lesson, the Internet has become a catalyst for radicalization, in reference to the recruiting of terrorists. Processes that previously might have taken a few months or even a year - to do from following a benign ideology to traveling abroad to become a foreign fighter - in some cases take only a few weeks.
True
Which of the following was mentioned in the lesson as an example of a cyber attack which occurred during a time of revolution or conflict?
All of the above
According to the TED talk from the lesson, in the face of possible cyber warfare and cyberattacks, the government has to "step up its game" and become responsible for not just attacks on the federal government and critical infrastructures, it needs to become engaged in the defense of major industry organizations such as Sony.
False