Cybersecurity Essentials v1.1 Chapter 8 Quiz Answers
1. An auditor is asked to assess the LAN of a company for potential threats. What are three potential threats the auditor may point out? (Choose three.)
a misconfigured firewall*
unauthorized port scanning and network probing*
unlocked access to network equipment*
complex passwords
locked systems
the acceptable use policy
2. As part of HR policy in a company, an individual may opt-out of having information shared with any third party other than the employer. Which law protects the privacy of personal shared information?
GLBA*
PCI
SOX
FIRPA
3. As a security professional, there is a possibility to have access to sensitive data and assets. What is one item a security professional should understand in order to make informed ethical decisions?
partnerships
potential gain
laws governing the data*
cloud providers
potential bonus
4. A security professional is asked to perform an analysis of the current state of a company network. What tool would the security professional use to scan the network only for security risks?
vulnerability scanner*
malware
packet analyzer
pentest
5. A consultant is hired to make recommendations on managing device threats in a company. What are three general recommendations that can be made? (Choose three.)
Enforce strict HR policies.
Disable administrative rights for users.*
Remove content filtering.
Enable media devices.
Enable automated antivirus scans.*
Enable screen lockout.*
6. What three services does CERT provide? (Choose three.)
enforce software standards
develop tools, products, and methods to analyze vulnerabilities*
develop tools, products, and methods to conduct forensic examinations*
create malware tools
resolve software vulnerabilities*
develop attack tools
7. What are two items that can be found on the Internet Storm Center website? (Choose two.)
InfoSec reports*
historical information
InfoSec job postings*
current laws
8. What can be used to rate threats by an impact score to emphasize important vulnerabilities?
CERT
ACSC
NVD*
ISC
9. A breach occurs in a company that processes credit card information. Which industry specific law governs credit card data protection?
PCI DSS*
ECPA
SOX
GLBA
10. Why is Kali Linux a popular choice in testing the network security of an organization?
It is a network scanning tool that prioritizes security risks.
It can be used to intercept and log network traffic.
It can be used to test weaknesses by using only malicious software.
It is an open source Linux security distribution and contains over 300 tools.*
11. A company is attempting to lower the cost in deploying commercial software and is considering a cloud based service. Which cloud based service would be best to host the software?
RaaS
SaaS*
PaaS
IaaS
12. An organization has implemented a private cloud infrastructure. The security administrator is asked to secure the infrastructure from potential threats. What three tactics can be implemented to protect the private cloud? (Choose three.)
Update devices with security fixes and patches.*
Hire a consultant.
Disable firewalls.
Test inbound and outbound traffic.*
Disable ping, probing, and port scanning.*
Grant administrative rights.
13. A school administrator is concerned with the disclosure of student information due to a breach. Under which act is student information protected?
FERPA*
HIPPA
CIPA
COPPA
14. What are the three broad categories for information security positions? (Choose three.)
Definers*
doers
seekers
monitors*
builders*
creators
15. What are two potential threats to applications? (Choose two.)
data loss*
social engineering
power interruptions
unauthorized Access*
16. If a person knowingly accesses a government computer without permission, what federal act laws would the person be subject to?
GLBA
ECPA
SOX
CFAA*
17. A company has had several incidents involving users downloading unauthorized software, using unauthorized websites, and using personal USB devices. The CIO wants to put in place a scheme to manage the user threats. What three things might be put in place to manage the threats? (Choose three.)
Disable CD and USB access.*
Monitor all activity by the users.
Provide security awareness training.*
Use content filtering.*
Change to thin clients.
Implement disciplinary action.
18. What are three disclosure exemptions that pertain to the FOIA? (Choose three.)
public information from financial institutions
confidential business information*
non-geological information regarding wells
information specifically non-exempt by statue
national security and foreign policy information*
law enforcement records that implicate one of a set of enumerated concerns*
19. Unauthorized visitors have entered a company office and are walking around the building. What two measures can be implemented to prevent unauthorized visitor access to the building? (Choose two.)
Establish policies and procedures for guests visiting the building.*
Conduct security awareness training regularly.*
Lock cabinets.
Prohibit exiting the building during working hours.