Pg7 Flashcards

(17 cards)

1
Q

A company is deploying new vulnerability scanning software to assess its systems. The current network is highly segmented, and the networking team wants to minimize the number of unique firewall rules. Which of the following scanning techniques would be most efficient to achieve the objective?

A. Deploy agents on all systems to perform the scans
B. Deploy a central scanner and perform non-credentialed scans
C. Deploy a cloud-based scanner and perform a network scan
D. Deploy a scanner sensor on every segment and perform credentialed scans

A

Deploy agents on all systems to perform the scans

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Executives at an organization email sensitive financial information to external business partners when negotiating valuable contracts. To ensure the legal validity of these messages, the cybersecurity team recommends a digital signature be added to emails sent by the executives. Which of the following are the primary goals of this recommendation? (Choose two.)

A. Confidentiality
B. Integrity
C. Privacy
D. Anonymity
E. Non-reduplication
F. Authorization

A

Non-reduplication
Integrity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

A security administrator needs to import PII data records from the production environment to the test environment for testing purposes. Which of the following would best protect data confidentiality?

A. Data masking
B. Hashing
C. Watermarking
D. Encoding

A

A. Data masking

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

The email system administrator for an organization configured DKIM signing for all email legitimately sent by the organization. Which of the following would most likely indicate an email is malicious if the company’s domain name is used as both the sender and the recipient?

A. The message fails a DMARC check
B. The sending IP address is the hosting provider
C. The signature does not meet corporate standards
D. The sender and reply address are different

A

The message fails a DMARC check

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

During an incident involving phishing, a security analyst needs to find the source of the malicious email. Which of the following techniques would provide the analyst with this information?

A. Header analysis
B. Packet capture
C. SSL inspection
D. Reverse engineering

A

Header analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

An analyst wants to ensure that users only leverage web-based software that has been pre-approved by the organization. Which of the following should be deployed?

A. Blocklisting
B. Allowlisting
C. Graylisting
D. Webhooks

A

Allowlisting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

During a cybersecurity incident, one of the web servers at the perimeter network was affected by ransomware. Which of the following actions should be performed immediately?

A. Shut down the server.
B. Reimage the server.
C. Quarantine the server.
D. Update the OS to latest version.

A

Quarantine the server.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

An organization recently changed its BC and DR plans. Which of the following would best allow for the incident response team to test the changes without any impact to the business?

A. Perform a tabletop drill based on previously identified incident scenarios.
B. Simulate an incident by shutting down power to the primary data center.
C. Migrate active workloads from the primary data center to the secondary location.
D. Compare the current plan to lessons learned from previous incidents.

A

Perform a tabletop drill based on previously identified incident scenarios.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Security analysts review logs on multiple servers on a daily basis. Which of the following implementations will give the best central visibility into the events occurring throughout the corporate environment without logging in to the servers individually?

A. Deploy a database to aggregate the logging
B. Configure the servers to forward logs to a SIEM
C. Share the log directory on each server to allow local access.
D. Automate the emailing of logs to the analysts.

A

Configure the servers to forward logs to a SIEM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Following a recent security incident, the Chief Information Security Officer is concerned with improving visibility and reporting of malicious actors in the environment. The goal is to reduce the time to prevent lateral movement and potential data exfiltration. Which of the following techniques will best achieve the improvement?

A. Mean time to detect
B. Mean time to respond
C. Mean time to remediate
D. Service-level agreement uptime

A

Mean time to detect

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

After identifying a threat, a company has decided to implement a patch management program to remediate vulnerabilities. Which of the following risk management principles is the company exercising?

A. Transfer
B. Accept
C. Mitigate
D. Avoid

A

Mitigate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

A security analyst discovers an ongoing ransomware attack while investigating a phishing email. The analyst downloads a copy of the file from the email and isolates the affected workstation from the network. Which of the following activities should the analyst perform next?

A. Wipe the computer and reinstall software
B. Shut down the email server and quarantine it from the network
C. Acquire a bit-level image of the affected workstation
D. Search for other mail users who have received the same file

A

Search for other mail users who have received the same file

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

The security analyst received the monthly vulnerability report. The following findings were included in the report:

  • Five of the systems only required a reboot to finalize the patch application
  • Two of the servers are running outdated operating systems and cannot be patched

The analyst determines that the only way to ensure these servers cannot be compromised is to isolate them. Which of the following approaches will best minimize the risk of the outdated servers being compromised?

A. Compensating controls
B. Due diligence
C. Maintenance windows
D. Passive discovery

A

Compensating controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

An incident response analyst is taking over an investigation from another analyst. The investigation has been going on for the past few days. Which of the following steps is most important during the transition between the two analysts?

A. Identify and discuss the lessons learned with the prior analyst.
B. Accept all findings and continue to investigate the next item target.
C. Review the steps that the previous analyst followed.
D. Validate the root cause from the prior analyst.

A

Review the steps that the previous analyst followed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

A recent penetration test discovered that several employees were enticed to assist attackers by visiting specific websites and running downloaded files when prompted by phone calls. Which of the following would best address this issue?

A. Increasing training and awareness for all staff
B. Ensuring that malicious websites cannot be visited
C. Blocking all scripts downloaded from the internet
D. Disabling all staff members’ ability to run downloaded applications

A

Increasing training and awareness for all staff

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

A security administrator has been notified by the IT operations department that some vulnerability reports contain an incomplete list of findings. Which of the following methods should be used to resolve this issue?

A. Credentialed scar
B. External scan
C. Differential scan
D. Network scan

A

Credentialed scar

17
Q

An organization enabled a SIEM rule to send an alert to a security analyst distribution list when ten failed logins occur within one minute. However, the control was unable to detect an attack with nine failed logins. Which of the following best represents what occurred?

A. False positive
B. True negative
C. False negative
D. True positive

A

False negative