lab 18 Flashcards

1
Q

Which of the following are headings or section titles in the security policy document from the SANS organization? (Select all that apply)

Overview
Purpose
Scope
Policy
Policy Compliance
Revision History
Redactions

A

Overview
Purpose
Scope
Policy
Policy Compliance
Revision History

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

The Server Security Policy references two other policies related to this policy document’s concepts. What are those two other policies?

Audit Policy
DMZ Equipment Policy
Software Installation Policy
Password Protection Policy
Wireless Communication Policy

A

Audit Policy
DMZ Equipment Policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

The Microsoft Windows Server benchmarks are available for a wide range of versions of this OS. Which of the following are included on the list at CIS?

Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2022
Microsoft Windows Server 2019
Microsoft Windows Server 2016

A

Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2022
Microsoft Windows Server 2019
Microsoft Windows Server 2016

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

CIS Benchmarks are available for which of the following products?

Amazon Web Services
Apple iOS
Docker
NGINX
pfSense Firewall
Zoom

A

Amazon Web Services
Apple iOS
Docker
NGINX
pfSense Firewall
Zoom

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which of the following is not a Category of Security Policy Templates from the SANS website?

Retired
Incident Handling
Application Security
IoT and ICS Security

A

IoT and ICS Security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which of the following is a category of Benchmark from CIS?

DevSecOps Tools
IoT devices
Edge computing
Imbedded systems
Static OS solutions

A

DevSecOps Tools

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Once a security template, baseline, or benchmark has been obtained from a third-party, what tasks are your responsibility? (Select two)

Public dissemination
Scoping to your business objectives
Tailoring to your system functions
Providing support documentation

A

Scoping to your business objectives
Tailoring to your system functions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Network security baselines describe a set of minimum security controls and configurations for a network. They provide a starting point for the hardening process.

True
False

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Center for Internet Security (CIS) Benchmarks can be applied directly to production systems for optimal security compliance.

False
True

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly