BAsset criticality assessment "" (Risks and Associated Risk Levels)
CProbability of Loss X Loss
D(Countermeasures + Magnitude of Impact) "" (Reports from prior risk assessments)
A computer Risk Policy is a set of ideas to be implemented to overcome the risk associated with computer security incidents. Identify the procedure that is NOT part of the computer risk policy?
AProcedure to identify security funds to hedge risk
BProcedure to monitor the efficiency of security controls
CProcedure for the ongoing training of employees authorized to access the system
DProvisions for continuing support if there is an interruption in the system or if the system crashes
Risk management consists of three processes, risk assessment, mitigation and evaluation. Risk assessment determines the extent of the potential threat and the risk associated with an IT system through its SDLC. How many primary steps does NIST's risk assessment methodology involve?
ATwelve
BFour
CSix
DNine
Question 6
Network & Mobile Incidents
0
Question 7
Network & Mobile Incidents
Question 8
Insider Threats
Question 9
Incident Response and Handling
Question 10
Incident Response and Handling
Question 11
Malware Incidents
Question 12
Network & Mobile Incidents
Question 13
Incident Response and Handling
Question 14
Incident Response and Handling
Question 15
Insider Threats
Question 16
Process Handling
Question 17
Process Handling
Question 18
Process Handling
Question 19
Insider Threats
Question 20
Malware Incidents
Question 21
Insider Threats
Question 22
Incident Response and Handling
Question 23
Incident Response and Handling
Question 24
Incident Response and Handling
Question 25
Email Security Incidents
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ad
Want a break from the ads?
Become a Supporter and enjoy a completely ad-free experience, plus unlock Learn Mode, Exam Mode, AstroTutor AI, and more.
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Identify the network security incident where intended authorized users are prevented from using system, network, or applications by flooding the network with high volume of traffic that consumes all existing network resources.
AURL Manipulation
BXSS Attack
CSQL Injection
DDenial of Service Attack
A distributed Denial of Service (DDoS) attack is a more common type of DoS Attack, where a single system is targeted by a large number of infected machines over the Internet. In a DDoS attack, attackers first infect multiple systems which are known as:
ATrojans
BZombies
CSpyware
DWorms
An organization faced an information security incident where a disgruntled employee passed sensitive access control information to a competitor. The organization's incident response manager, upon investigation, found that the incident must be handled within a few hours on the same day to maintain business continuity and market competitiveness. How would you categorize such information security incident?
AHigh level incident
BMiddle level incident
CUltra-High level incident
DLow level incident
Which of the following is an appropriate flow of the incident recovery steps?
Incident handling and response steps help you to detect, identify, respond and manage an incident. Which of the following steps focus on limiting the scope and extent of an incident?
AEradication
BContainment
CIdentification
DData collection
Identify the malicious program that is masked as a genuine harmless program and gives the attacker unrestricted access to the user's information and system.
These programs may unleash dangerous programs that may erase the unsuspecting user's disk and send the victim's credit card numbers and passwords to a stranger.
ACookie tracker
BWorm
CTrojan
DVirus
A US Federal agency network was the target of a DoS attack that prevented and impaired the normal authorized functionality of the networks. According to agency's reporting timeframe guidelines, this incident should be reported within two (2) HOURS of discovery/detection if the successful attack is still ongoing and the agency is unable to successfully mitigate the activity. Which incident category of the US Federal Agency does this incident belong to?
ACAT 5
BCAT 1
CCAT 2
DCAT 6
US-CERT and Federal civilian agencies use the reporting timeframe criteria in the federal agency reporting categorization. What is the timeframe required to report an incident under the CAT 4 Federal Agency category?
AWeekly
BWithin four (4) hours of discovery/detection if the successful attack is still ongoing and agency is unable to successfully mitigate activity
CWithin two (2) hours of discovery/detection
DMonthly
Which test is conducted to determine the incident recovery procedures effectiveness?
ALive walk-throughs of procedures
BScenario testing
CDepartment-level test
DFacility-level test
The insider risk matrix consists of technical literacy and business process knowledge vectors. Considering the matrix, one can conclude that:
AIf the insider's technical literacy is low and process knowledge is high, the risk posed by the threat will be insignificant.
BIf the insider's technical literacy and process knowledge are high, the risk posed by the threat will be insignificant.
CIf the insider's technical literacy is high and process knowledge is low, the risk posed by the threat will be high.
DIf the insider's technical literacy and process knowledge are high, the risk posed by the threat will be high.
Contingency planning enables organizations to develop and maintain effective methods to handle emergencies. Every organization will have its own specific requirements that the planning should address. There are five major components of the IT contingency plan, namely supporting information, notification activation, recovery and reconstitution and plan appendices. What is the main purpose of the reconstitution plan?
ATo restore the original site, tests systems to prevent the incident and terminates operations
BTo define the notification procedures, damage assessments and offers the plan activation
CTo provide the introduction and detailed concept of the contingency plan
DTo provide a sequence of recovery activities with the help of recovery procedures
Which policy recommends controls for securing and tracking organizational resources:
AAccess control policy
BAdministrative security policy
CAcceptable use policy
DAsset control policy
Identify a standard national process which establishes a set of activities, general tasks and a management structure to certify and accredit systems that will maintain the information assurance (IA) and security posture of a system or site.
ANIASAP
BNIAAAP
CNIPACP
DNIACAP
When an employee is terminated from his or her job, what should be the next immediate step taken by an organization?
AAll access rights of the employee to physical locations, networks, systems, applications and data should be disabled
BThe organization should enforce separation of duties
CThe access requests granted to an employee should be documented and vetted by the supervisor
DThe organization should monitor the activities of the system administrators and privileged users who have permissions to access the sensitive information
A Host is infected by worms that propagates through a vulnerable service; the sign(s) of the presence of the worm include:
ADecrease in network usage
BEstablished connection attempts targeted at the vulnerable services
CSystem becomes instable or crashes
DAll the above
Which of the following is NOT one of the common techniques used to detect Insider threats:
ASpotting an increase in their performance
BObserving employee tardiness and unexplained absenteeism
CObserving employee sick leaves
DSpotting conflicts with supervisors and coworkers
Which of the following terms may be defined as "a measure of possible inability to achieve a goal, objective, or target within a defined security, cost plan and technical limitations that adversely affects the organization's operation and revenues?
ARisk
BVulnerability
CThreat
DIncident Response
An incident recovery plan is a statement of actions that should be taken before, during or after an incident. Identify which of the following is NOT an objective of the incident recovery plan?
ACreating new business processes to maintain profitability after incident
BProviding a standard for testing the recovery plan
CAvoiding the legal liabilities arising due to incident
DProviding assurance that systems are reliable
Which of the following incident recovery testing methods works by creating a mock disaster, like fire to identify the reaction of the procedures that are implemented to handle such situations?
AScenario testing
BFacility testing
CLive walk-through testing
DProcedure testing
A computer virus hoax is a message warning the recipient of non-existent computer virus. The message is usually a chain e-mail that tells the recipient to forward it to every one they know. Which of the following is NOT a symptom of virus hoax message?
AThe message prompts the end user to forward it to his / her e-mail contact list and gain monetary benefits in doing so
BThe message from a known email id is caught by SPAM filters due to change of filter settings
CThe message warns to delete certain files if the user does not take appropriate action
DThe message prompts the user to install Anti-Virus