$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))_______________________________________________________________________________________________________________________________________________________
and Engineering
D488 - Cybersecurity
(CASP+).pdf!#()*_*$_!*$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))____________________________________________________________________________________________________________________________
Architecture and Engineering (CASP+).pdf!#()*_*$_!*$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))____________________________________________________________________________________________
Terms in this set (1074)
A/an __________________ arises from an actor the C. Insider threat
organization has identified and granted access. Which type of
threat actor could intentionally delete key files after being
given access to sensitive systems?
A. Hacktivist
B. Organized crime
C. Insider threat
D. Competitor
An administrator creates a SPAN port that feeds traffic to a B. NIDS (network intrusion detection system)
security tool. The security tool monitors suspicious network
traffic and does not block traffic. What type of tool is used?
A. NIPS (network intrusion prevention system)
B. NIDS (network intrusion detection system)
C. FIM (File Integrity Monitoring)
D. DLP (Data Loss Prevention)
After a Certifying Authority accredits a system, what formal C. ATO (Authorization to Operate)
letter is granted to the system owner, allowing the system to
operate for a period of three years?
A. Certification
B. POAM (Plan of Actions and Milestones)
C. ATO (Authorization to Operate)
D. Accreditation
$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))_______________________________________________________________________________________________________________________________________________________
and Engineering
D488 - Cybersecurity
(CASP+).pdf!#()*_*$_!*$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))____________________________________________________________________________________________________________________________
Architecture and Engineering (CASP+).pdf!#()*_*$_!*$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))____________________________________________________________________________________________
,$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))_______________________________________________________________________________________________________________________________________________________
and Engineering
D488 - Cybersecurity
(CASP+).pdf!#()*_*$_!*$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))____________________________________________________________________________________________________________________________
Architecture and Engineering (CASP+).pdf!#()*_*$_!*$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))____________________________________________________________________________________________
After a system compromise, a security engineer attempts to A. Data exfiltration
connect to an adversary's system as a hack-back action. What
incident type does the engineer respond to?
A. Data exfiltration
B. Ransomware
C. Social Engineering
D. Triage Event
APIs play a major role in interacting with which technology C. Containers
that allows applications to run independently in virtual
instances?
A. SOAR (Security orchestration, automation, and response)
B. IdP (identity provider)
C. Containers
D. Traditional VMs
Application developers place a new piece of software under a A. Security misconfiguration
stress test. During the process, it is discovered that default
administrative credentials set within the software cause a
vulnerability. What vulnerability is a concern to the team?
A. Security misconfiguration
B. Poor exception handling
C. Weak cryptography implementations
D. Information disclosure
$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))_______________________________________________________________________________________________________________________________________________________
and Engineering
D488 - Cybersecurity
(CASP+).pdf!#()*_*$_!*$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))____________________________________________________________________________________________________________________________
Architecture and Engineering (CASP+).pdf!#()*_*$_!*$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))____________________________________________________________________________________________
,$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))_______________________________________________________________________________________________________________________________________________________
and Engineering
D488 - Cybersecurity
(CASP+).pdf!#()*_*$_!*$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))____________________________________________________________________________________________________________________________
Architecture and Engineering (CASP+).pdf!#()*_*$_!*$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))____________________________________________________________________________________________
An application is experiencing a security flaw where the D. TOC (Time of Check)
system checks the state of a resource, but by the time it
performs an action based on that check, the resource has
changed state. What is this issue called?
A. ASLR (Address Space Layout Randomization)
B. Race condition
C. DEP (Data Execution Protection)
D. TOC (Time of Check)
An application server is the constant target of a buffer overflow A. Identify areas of memory that contain executable code
exploit. To prevent further attacks, a systems administrator
uses an operating system with data execution protection (DEP).
How does this solution proactively help to prevent a buffer
overflow?
A. Identify areas of memory that contain executable code
B. Boundary checks prior to using data
C. Applying security patches
D. Unable to locate the memory addresses
An application specialist suggests using a particular application A. Containers
in a virtualized environment to avoid configuring additional
workstations for the sake of using one piece of software. What
does the specialist suggest using?
A. Containers
B. Thin client
C. Minimal OS
D. Thick client
$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))_______________________________________________________________________________________________________________________________________________________
and Engineering
D488 - Cybersecurity
(CASP+).pdf!#()*_*$_!*$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))____________________________________________________________________________________________________________________________
Architecture and Engineering (CASP+).pdf!#()*_*$_!*$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))____________________________________________________________________________________________
,$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))_______________________________________________________________________________________________________________________________________________________
and Engineering
D488 - Cybersecurity
(CASP+).pdf!#()*_*$_!*$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))____________________________________________________________________________________________________________________________
Architecture and Engineering (CASP+).pdf!#()*_*$_!*$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))____________________________________________________________________________________________
An application uses encrypted transactional data to record B. Blockchain
incoming and changing data sets. Which technology does the
application use?
A. Big data
B. Blockchain
C. Artificial intelligence
D. Deep learning
As part of a training exercise, the Lockheed Martin cyber kill B. Exploitation
chain is referenced by educators at a security firm. When
explaining that an adversary's tool was successfully delivered
and resulted in successful access to a private system, what step
in the chain do educators discuss?
A. Delivery
B. Exploitation
C. Installation
D. Weaponization
An attacker gains access to a sensitive shared folder. What B. Adjust ACL rules
might a security engineer configure to directly mitigate the
problem?
A. Enable Endpoint Protection
B. Adjust ACL rules
C. implement IDS rules
D. Deploy a script
$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))_______________________________________________________________________________________________________________________________________________________
and Engineering
D488 - Cybersecurity
(CASP+).pdf!#()*_*$_!*$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))____________________________________________________________________________________________________________________________
Architecture and Engineering (CASP+).pdf!#()*_*$_!*$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))____________________________________________________________________________________________
and Engineering
D488 - Cybersecurity
(CASP+).pdf!#()*_*$_!*$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))____________________________________________________________________________________________________________________________
Architecture and Engineering (CASP+).pdf!#()*_*$_!*$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))____________________________________________________________________________________________
Terms in this set (1074)
A/an __________________ arises from an actor the C. Insider threat
organization has identified and granted access. Which type of
threat actor could intentionally delete key files after being
given access to sensitive systems?
A. Hacktivist
B. Organized crime
C. Insider threat
D. Competitor
An administrator creates a SPAN port that feeds traffic to a B. NIDS (network intrusion detection system)
security tool. The security tool monitors suspicious network
traffic and does not block traffic. What type of tool is used?
A. NIPS (network intrusion prevention system)
B. NIDS (network intrusion detection system)
C. FIM (File Integrity Monitoring)
D. DLP (Data Loss Prevention)
After a Certifying Authority accredits a system, what formal C. ATO (Authorization to Operate)
letter is granted to the system owner, allowing the system to
operate for a period of three years?
A. Certification
B. POAM (Plan of Actions and Milestones)
C. ATO (Authorization to Operate)
D. Accreditation
$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))_______________________________________________________________________________________________________________________________________________________
and Engineering
D488 - Cybersecurity
(CASP+).pdf!#()*_*$_!*$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))____________________________________________________________________________________________________________________________
Architecture and Engineering (CASP+).pdf!#()*_*$_!*$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))____________________________________________________________________________________________
,$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))_______________________________________________________________________________________________________________________________________________________
and Engineering
D488 - Cybersecurity
(CASP+).pdf!#()*_*$_!*$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))____________________________________________________________________________________________________________________________
Architecture and Engineering (CASP+).pdf!#()*_*$_!*$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))____________________________________________________________________________________________
After a system compromise, a security engineer attempts to A. Data exfiltration
connect to an adversary's system as a hack-back action. What
incident type does the engineer respond to?
A. Data exfiltration
B. Ransomware
C. Social Engineering
D. Triage Event
APIs play a major role in interacting with which technology C. Containers
that allows applications to run independently in virtual
instances?
A. SOAR (Security orchestration, automation, and response)
B. IdP (identity provider)
C. Containers
D. Traditional VMs
Application developers place a new piece of software under a A. Security misconfiguration
stress test. During the process, it is discovered that default
administrative credentials set within the software cause a
vulnerability. What vulnerability is a concern to the team?
A. Security misconfiguration
B. Poor exception handling
C. Weak cryptography implementations
D. Information disclosure
$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))_______________________________________________________________________________________________________________________________________________________
and Engineering
D488 - Cybersecurity
(CASP+).pdf!#()*_*$_!*$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))____________________________________________________________________________________________________________________________
Architecture and Engineering (CASP+).pdf!#()*_*$_!*$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))____________________________________________________________________________________________
,$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))_______________________________________________________________________________________________________________________________________________________
and Engineering
D488 - Cybersecurity
(CASP+).pdf!#()*_*$_!*$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))____________________________________________________________________________________________________________________________
Architecture and Engineering (CASP+).pdf!#()*_*$_!*$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))____________________________________________________________________________________________
An application is experiencing a security flaw where the D. TOC (Time of Check)
system checks the state of a resource, but by the time it
performs an action based on that check, the resource has
changed state. What is this issue called?
A. ASLR (Address Space Layout Randomization)
B. Race condition
C. DEP (Data Execution Protection)
D. TOC (Time of Check)
An application server is the constant target of a buffer overflow A. Identify areas of memory that contain executable code
exploit. To prevent further attacks, a systems administrator
uses an operating system with data execution protection (DEP).
How does this solution proactively help to prevent a buffer
overflow?
A. Identify areas of memory that contain executable code
B. Boundary checks prior to using data
C. Applying security patches
D. Unable to locate the memory addresses
An application specialist suggests using a particular application A. Containers
in a virtualized environment to avoid configuring additional
workstations for the sake of using one piece of software. What
does the specialist suggest using?
A. Containers
B. Thin client
C. Minimal OS
D. Thick client
$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))_______________________________________________________________________________________________________________________________________________________
and Engineering
D488 - Cybersecurity
(CASP+).pdf!#()*_*$_!*$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))____________________________________________________________________________________________________________________________
Architecture and Engineering (CASP+).pdf!#()*_*$_!*$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))____________________________________________________________________________________________
,$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))_______________________________________________________________________________________________________________________________________________________
and Engineering
D488 - Cybersecurity
(CASP+).pdf!#()*_*$_!*$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))____________________________________________________________________________________________________________________________
Architecture and Engineering (CASP+).pdf!#()*_*$_!*$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))____________________________________________________________________________________________
An application uses encrypted transactional data to record B. Blockchain
incoming and changing data sets. Which technology does the
application use?
A. Big data
B. Blockchain
C. Artificial intelligence
D. Deep learning
As part of a training exercise, the Lockheed Martin cyber kill B. Exploitation
chain is referenced by educators at a security firm. When
explaining that an adversary's tool was successfully delivered
and resulted in successful access to a private system, what step
in the chain do educators discuss?
A. Delivery
B. Exploitation
C. Installation
D. Weaponization
An attacker gains access to a sensitive shared folder. What B. Adjust ACL rules
might a security engineer configure to directly mitigate the
problem?
A. Enable Endpoint Protection
B. Adjust ACL rules
C. implement IDS rules
D. Deploy a script
$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))_______________________________________________________________________________________________________________________________________________________
and Engineering
D488 - Cybersecurity
(CASP+).pdf!#()*_*$_!*$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))____________________________________________________________________________________________________________________________
Architecture and Engineering (CASP+).pdf!#()*_*$_!*$__________________________)(&)$*&!)($)(*&&*^(&(#()))))))))))))))))))))))))))))))____________________________________________________________________________________________