OS 601 — Reviewer for Finals

OS 601 — Reviewer for Finals

Prelim Quiz 1

Which of the following malicious insider action that the user has appropriate system rights without a need to know and takes place when a user has permissions by the system access controls but the event should not take place because it violates organization policy?
Correct answer: Snooping
Which of the following risk minimization strategy that the risk responsibility by partially shifting the risk to either outsourcing security service provision bodies or buying insurance?
Correct answer: Transferring
Loss of information (hardcopy, removable media, laptop) that was taken outside by an authorized insider (e.g. theft by an outsider)
Correct answer: Disclosure of valuable information due to loss
Which of the following threat that threat actor install a virus on a server in the network using local admin rights?
Correct answer: Use of authorized network access to accidentally install malicious software
Which of the following malicious insider types that insider has or can seize supervisory control and as such can either operate below the level at which logs are taken or can use privileges to erase the logs?
Correct answer: Clandestine
The security measures as a cost of doing business. Risk retention is a reasonable strategy for risks where the cost of investment or insuring against the risk would be greater over time than the total losses sustained.
Correct answer: Accepting
Which of the following risk minimization strategy that when the severity of the impact of the risk outweighs the benefit that is gained from having or using the information?
Correct answer: Avoiding
Which of the following malicious insider type hat full access to a computer system who impersonates a legitimate user?
Correct answer: Masquerader
Which of the following insider threat motivation that intentionally misused authorized access to systems or networks with the intention of obtaining property or services from an organization unjustly through deception or trickery?
Correct answer: Fraud
Which of the following threat that unintentionally misuses physical access by throwing away valuable information?
Correct answer: Unintentional destruction of valuable information
Install a virus on a server in the network using local admin rights.
Correct answer: Abuse network access to install malicious software
Reduction or ‘mitigation’ is the primary risk management strategy.
Correct answer: Reducing
Which of the following threat that taking valuable information (hardcopy, removable media) out of the organization?
Correct answer: Abuse physical access to transport and/or distribute information
Which of the following insider threat that people who attack computer systems to cause fear for political gain?
Correct answer: Terrorists
The process of safeguarding the confidentiality, integrity and availability of information.
Correct answer: Information security
Which of the following malicious insider type that involves the misuse of authorized access both to the system and to its data?
Correct answer: Misfeasor
Which of the following insider threat that people who attack computer systems to cause damage?
Correct answer: Vandals
Which of the following insider threat that People within the organization who deliberately abuse or misuse computer systems and their information?
Correct answer: Disgruntled employees
Which of the following insider threat motivation that intentionally misused authorized access to systems or networks with the intention of stealing confidential or proprietary information from an organization?
Correct answer: Espionage
Which of the following insider threat that insiders misused authorized access to systems or networks with the intention of harming an organization?
Correct answer: Insider IT Sabotage

Midterm Quiz 2

Which compliance metric measures an organization's risk level based on the likelihood and impact of compliance violations?
Correct answer: Compliance risk assessment score
Which of the following is not an example of a data protection compliance regulation?
Correct answer: PCI DSS
What does patching effectiveness metric measure?
Correct answer: How quickly vulnerabilities are patched after they have been identified.
Which vulnerability management metric measures the time it takes for vulnerabilities to be remediated after they are discovered?
Correct answer: Time to remediate
What are cybersecurity performance metrics used for?
Correct answer: All of the above
What is vulnerability scans?
Correct answer: A process of identifying vulnerabilities in systems and networks.
Which compliance metric measures the compliance level of third-party vendors, suppliers, or partners?
Correct answer: Third-party compliance assessment
Which compliance metric measures the effectiveness of an organization's compliance program based on the number of incidents, fines, or penalties?
Correct answer: Compliance program effectiveness
Which of the following is a common security metric?
Correct answer: Mean time to respond (MTTR)
Which of the following is not an example of a vulnerability management metric?
Correct answer: Incident resolution time
What is security metrics?
Correct answer: A systematic approach to measuring and assessing the effectiveness of an organization's security program.
Which compliance metric measures the percentage of employees who have completed mandatory compliance training?
Correct answer: Compliance training completion rate
Which of the following is not an example of an incident response metric?
Correct answer: Compliance training completion rate
What does phishing campaign success rate metric measure?
Correct answer: The percentage of employees who fall for a simulated phishing attack.
Which incident response metric measures the frequency of incidents that occur over a certain period?
Correct answer: Number of incidents per week/month/quarter
Which vulnerability management metric measures the rate at which previously remediated vulnerabilities reappear in an organization's systems?
Correct answer: Vulnerability reoccurrence rate
Which of the following vulnerability management metrics can help identify areas where additional scanning or testing is needed?
Correct answer: Vulnerability discovery rate
Which of the following is not an example of a common performance metric in cybersecurity?
Correct answer: Inventory management metrics
Which incident response metric measures the severity of incidents based on their impact on the organization?
Correct answer: Incident severity
Which incident response metric measures the time it takes to respond to an incident once it has been detected?
Correct answer: Mean time to respond

Endterm Quiz 1

Which process involves learning every minute detail about each candidate?
Correct answer: Selection
What is the level of attention given to scrutinizing individual candidates during recruitment?
Correct answer: Minimal attention
How is the communication of vacancies done during recruitment?
Response: By distributing forms easily for candidates to apply
Correct answer: By scrutinizing individual candidates
What are the evaluation stages involved in the selection process?
Correct answer: Evaluating forms and written exams
What is the main purpose of the selection process?
Response: Identifying the most suitable candidate
Correct answer: Attracting more job seekers to apply
How is selection different from recruitment?
Correct answer: Selection is a negative process, while recruitment is a positive process.
What is the primary focus of recruiters during recruitment?
Correct answer: Identifying job needs and encouraging candidates to apply
What is the main objective of recruitment?
Correct answer: To attract suitable candidates
Which process is more time-consuming and expensive?
Correct answer: Selection
What is the main purpose of the recruitment process?
Response: Attracting more job seekers to apply
Correct answer: Identifying the most suitable candidate

Endterm Quiz 2

What is the main objective of recruitment?
Correct answer: To attract suitable candidates
Which security measure involves including security requirements and provisions in contracts with third-party vendors?
Correct answer: Contractual Security Provisions
What are some potential risks associated with third-party security?
Correct answer: Intellectual property theft
What is the purpose of third-party security measures in an organization?
Correct answer: To protect internal systems and data from external threats
Which security measure involves implementing encryption technologies to protect sensitive data from unauthorized access and theft?
Correct answer: Data Encryption
Which process is more time-consuming and expensive?
Correct answer: Selection
Which process involves learning every minute detail about each candidate?
Correct answer: Selection
What is the level of attention given to scrutinizing individual candidates during recruitment?
Correct answer: Minimal attention
What are some key components of effective third-party security measures?
Correct answer: Regular monitoring of third-party activities
What is the main purpose of the selection process?
Response: Identifying the most suitable candidate
Correct answer: Attracting more job seekers to apply
Why is it important for organizations to ensure that third-party vendors and contractors have adequate security measures in place?
Correct answer: It prevents reputational damage and legal liabilities
What are the evaluation stages involved in the selection process?
Correct answer: Evaluating forms and written exams
How is selection different from recruitment?
Correct answer: Selection is a negative process, while recruitment is a positive process.
What measure involves evaluating and assessing the security posture of third-party vendors before engaging in business with them?
Correct answer: Vendor Risk Management
How is the communication of vacancies done during recruitment?
Response: By distributing forms easily for candidates to apply
Correct answer: By scrutinizing individual candidates
What is the primary focus of recruiters during recruitment?
Correct answer: Identifying job needs and encouraging candidates to apply
What is the main purpose of the recruitment process?
Response: Attracting more job seekers to apply
Correct answer: Identifying the most suitable candidate
What security measure involves restricting access to sensitive systems and data based on the principle of least privilege?
Correct answer: Access Controls
Which security measure involves conducting regular assessments to identify vulnerabilities and assess the effectiveness of security controls?
Correct answer: Regular Security Audits
How can organizations mitigate third-party security risks?
Correct answer: Conducting thorough risk assessments

Midterm Exam

In a server room, you notice that the temperature is very high. What action should you take?
Correct answer: Turn on the air conditioning
What does the "number of security incidents" metric measure?
Correct answer: The number of security incidents that occur within a given period of time
Which metric measures the potential impact of a risk event on a business or project?
Correct answer: Risk Severity
Which of the following is the best way to troubleshoot a server that is not responding?
Correct answer: Check the event logs
What does the CIA triad stand for?
Correct answer: Confidentiality, Integrity and Availability.
Which metric measures how frequently a business is monitoring its risks?
Correct answer: Risk Monitoring Frequency
A user reports that they cannot access the company's network drive. What is the first thing you should do?
Correct answer: Check the user's permissions
What is the recommended way to ensure a server is secure?
Correct answer: All of the above
What does the "access control effectiveness" metric measure?
Correct answer: How well access controls are enforced and reviewed
Which metric measures the speed at which a risk can cause damage to a business?
Correct answer: Risk Velocity
Which metric measures the total amount of financial loss that a business may suffer if a specific risk event occurs?
Correct answer: Risk Exposure
Which of the following is an example of a compliance metric?
Correct answer: Compliance risk assessment score
What does the "compliance with security policies" metric measure?
Correct answer: How well employees adhere to security policies
What does the "mean time to detect (MTTD)" metric measure?
Correct answer: The time it takes to detect a security incident
Which of the following is an example of a vulnerability management metric?
Correct answer: Mean time to detect (MTTD)
Which metric measures how quickly a business can respond to a risk event?
Correct answer: Risk Response Time
What is Puppet and Chef?
Correct answer: Automation software
A client is unable to connect to the internet. What should be your first troubleshooting step?
Correct answer: Check the internet connection
A server is running out of disk space. What should be your next step?
Correct answer: Delete unnecessary files
What must a piece of security intelligence correspond to in order to be useful?
Correct answer: A known vulnerability.
What is a computer operator responsible for?
Correct answer: Performing routine maintenance
What are some tasks that can be automated using Perl/Python or shell scripts?
Correct answer: All of the above
What is a database administrator responsible for?
Correct answer: Maintaining a database system
A user is unable to access a shared drive. What should be your first troubleshooting step?
Correct answer: Check if the shared drive is connected
What is AWS?
Correct answer: Cloud infrastructure
Which metric measures how quickly a business can respond to a risk event?
Correct answer: Risk Response Time
Which of the following measures the time it takes to resolve an incident once it has been detected?
Correct answer: Incident resolution time
Which metric measures how well access controls are enforced and how frequently they are reviewed?
Correct answer: Access control effectiveness
What does the "vulnerability scans" metric measure?
Correct answer: The number of vulnerability scans conducted on systems and networks
Which metric measures how well a business's risk mitigation strategies are working?
Correct answer: Risk Mitigation Effectiveness
Which of the following measures the number of vulnerabilities identified that are not actually exploitable or do not require remediation?
Correct answer: False positive rate
What is source control?
Correct answer: Managing changes to source code
What is an APT?
Correct answer: A cyber attack initiated by an organization whose goal is to secure long-term access to an IT
organization's internal networks and data.
What does the "phishing campaign success rate" metric measure?
Correct answer: The percentage of employees who fall for a simulated phishing attack
What are some duties of a system administrator?
Correct answer: All of the above
What is a security administrator responsible for?
Correct answer: Administration of security devices such as firewalls
What is the recommended way to monitor a server's performance?
Correct answer: Use performance monitoring tools
What is the goal of Security Intelligence?
Correct answer: To generate actionable data that drives the informed and targeted implementation of security controls and countermeasures.
What does the "number of security incidents" metric measure?
Correct answer: The number of security incidents that occur within a given period of time
What is a system administrator responsible for?
Correct answer: Managing computer systems
What are performance metrics in cybersecurity?
Correct answer: Quantitative and qualitative indicators used to evaluate the effectiveness of security controls,
processes, and technologies in protecting an organization's assets against cyber threats
Which metric measures the potential impact of a risk on a business or project?
Correct answer: Risk Impact Assessment
What is a network administrator responsible for?
Correct answer: Maintaining network infrastructure
What does TTP refer to?
Correct answer: The methodology that cyber attacks used to execute the attack against the network.
What does GDPR stand for?
Correct answer: General Data Protection Regulation
What does a system administrator need to ensure about the computers they manage?
Correct answer: They meet the needs of the users
What does the "patching effectiveness" metric measure?
Correct answer: How quickly vulnerabilities are patched after they have been identified
Which metric measures how quickly a business can identify a potential risk?
Correct answer: Risk Identification Time
What is required for data to count as Security Intelligence?
Correct answer: All of the above.
Which of the following measures the compliance level of third-party vendors, suppliers, or partners?
Correct answer: Third-party compliance assessment
What does MTTD stand for?
Correct answer: Mean time to respond
Which metric measures the time it takes to detect a security incident?
Correct answer: Mean time to detect (MTTD)
What is the importance of real-time monitoring in Security Intelligence?
Correct answer: It allows IT organizations to gather security intelligence in real-time.
What does the "mean time to respond (MTTR)" metric measure?
Correct answer: The time it takes to respond to a security incident
Which of the following is an example of an incident response metric?
Correct answer: Number of incidents per week/month/quarter
Which metric measures the likelihood of a risk event occurring?
Correct answer: Risk Probability
You receive a report that a server has crashed. What should be your first step in resolving the issue?
Correct answer: Check the server logs
Which of the following measures the rate at which incidents are escalated to higher levels of management or response teams?
Correct answer: Escalation rate
What is the root account in system administration?
Correct answer: An account that has full (unrestricted) access
What is a web administrator responsible for?
Correct answer: Maintaining web server services