Part -1:
Question 1:
IDS stands for ___ .
- infection detection of system
- internal de-bugging system
- intrusion detection system
- The International Decryption Service
Question 2:
Continuous monitoring is necessary because security work is never done.
True
False
Question 3:
A teenager learning about computers and programming for the first time writes a simple program meant to disrupt the function of his sister's computer. While she's hanging out with friends at the mall. he enters his sister's IP address. launches the program. and waits to see what will happen. The teenager is an example of a _____.
- hacker
- DoS attacker
- script kiddie
- DDoS attacker
Question 4:
When risk is reduced to an acceptable level, the remaining risk is referred to as
- acceptable risk
- remaining risk
- residual risk
- low-impact risk
Question 5:
With proper security measures, a company can eliminate threats.
Question 6:
The term hacker is a general term that refers to all attackers who create intentional threats.
Question 7:
What is NOT a program overseen by National Cyber security and Communications integration Center
- DHS
- National Cyber Awareness System
- US-CERT
- ICS-CERT
Question 8:
- When does a threat/vulnerability pair occur?
- when a threat exploits a vulnerability
- when a vulnerability exploits a threat
- when an attacker exploits an unintentional threat when a threat creates a loss
Question 9:
In a DMZ. the firewall connected to the Internet allows access to the public-facing servers.
Question 10:
MITRE sponsors the CVE list. is
Question 11:
What can you control about threat/vulnerability pairs?
- the vulnerability
- the threat
- the loss
- the cost
Question 12:
Most companies should install antivirus software after connecting the server to the network.
Question 13:
What is NOT true about Operation Aurora?
- It attacked several private citizens.
- It originated in China.
- It attacked several private companies.
- It is an example of an APT attack.
Question 14:
What does CVE stand for?
- curriculum vitae
- Common Vulnerabilities and Exposures
- computer virus emergence
- common virus encounters
Question 15:
Hardening the server refers to ____.
- a mitigation technique that is a step towards protecting a vulnerable system
- a type of attack that removes the authorization to access a company's systems from high-level employees in a corporation
- the combination of all the steps that it takes to protect a vulnerable system and make it more secure than the default installation
- a type of attack that deletes vital data from a server
Question 16:
MITRE Is a part of MIT.
Question 17:
____ are acts that are hostile to an organization.
- All threats
- Intentional threats
- Human threats
- Unintentional threats
Question 18:
What is NOT an example of unintentional threat?
- The server for an Internet-based business crashes.
- An employee enters important data incorrectly on a day when he accidentally leaves his glasses at home.
- A swine flu epidemic causes a massive reduction in the labor force that maintains a company's systems.
- Malware written and run by a 'script kiddie' Just to see what he could do destroys a company's information database.
Question 19:
MITRE maintains the CVE list.
Question 20:
What is one source of risk reduction?
- eliminating the threat
- reducing the impact of the loss
- increasing the rate of the occurrence
- eliminating the threat/vulnerability pair
Part -2:
Question 1
IDS stands for _____.
Question 2
Continuous monitoring is necessary because security work is never done.
Question 3
A teenager learning about computers and programming for the first time writes a simple program meant to disrupt the function of his sister's computer. While she's hanging out with friends at the mall, he enters his sister's IP address, launches the program, and waits to see what will happen. The teenager is an example of a _____.
Question 4
When risk is reduced to an acceptable level, the remaining risk is referred to as ___
Question 5
With proper security measures. a company can eliminate threats.
Question 6
The term hacker is a general term that refers to all attackers who create intentional threats.
Question 7
What is NOT a program overseen by the National Cyber security and Communications Integration Center?
Question 8
When does a threat/vulnerability pair occur?
Question 9
In a DMZ, the firewall connected to the Internet allows access to the public-facing servers.
Question 10
MITRE sponsors the CVE list.
Question 11
What can you control about threat/vulnerability pairs?
Question 12
Most companies should install antivirus software after connecting the server to the network.
Question 13
What is NOT true about Operation Aurora?
Question 14
What does CVE stand for?
Question 15
Hardening the server refers to
Question 16
MITRE is a part of MIT.
Question 17
are acts that are hostile to an organization.
Question 18
What is NOT an example of unintentional threat?
Question 19
MITRE maintains the CVE list.
Question 20
What is one source of risk reduction?