You are required to keep track of file access.
Which type of auditing should be implemented? - Answers Object Access
Object Access - Answers This determines attempts to access files and other objects.
Process Tracking - Answers This determines events such as program activation and process exits.
Directory Services - Answers This determines whether the operating system generates audit events
when an AD DS object is accessed.
Audit Logon - Answers This determines whether the operating system generates audit events when a
user attempts to log on to the computer.
You are part of a cyber forensics team that needs to examine a hard drive for evidence. Your supervisor
tells you to first make a duplicate of the hard drive.
What is the purpose of making a duplicate of the hard drive? - Answers To preserve the original state of
the hard drive.
Surveillance cameras are installed around the building perimeter. - Answers Detective control
A failed disk is replaced and the backup is restored. - Answers Corrective control
New biometric door locks are installed. - Answers Preventive control
Which type of attack is directed toward a specific group of users to trick them into visiting an infected
website? - Answers Watering hole
Targets individuals through phone calls to gather compromising information. - Answers Vishing
Targets a high-profile victim. - Answers Whaling
Instead of luring, it involves directing an internet user to fake websites. - Answers Pharming
Which type of attack occurs when threat actors utilize botnets on several computers to overwhelm a
target web server? - Answers Distributed Denial-of-Service (DDoS)
An attacker has connected a laptop to a wireless network and attempts to lease all available IP
addresses from the DHCP server.
Which type of attack is occuring? - Answers DHCP Starvation
When an attacker responds to client DHCP and sends the client's incorrect IP address information such
as wrong default gateway or DNS server. - Answers DHCP Spoofing
, When an attacker alters DNS records to redirect online traffic to a fraudulent website. - Answers DNS
Spoofing
When the attacker creates IP packets with a modified source address to impersonate another computer
system. - Answers IP Spoofing
Which option is a common type of attack launched against IoT devices? - Answers DDos attack
What are the two classes of encryption algorithms? - Answers Asymmetric and Symmetric
What are the two most common hashing algorithms. - Answers SHA-2 and MD5
In which phase of the NIST Incident Response Life Cycle do you investigate network intrusion detection
sensor alerts? - Answers Detection & Analysis Phase
In which phase of the NIST Incident Response Life Cycle are you organizing to respond to security
incidents? - Answers Preparation Phase
In which phase of the NIST Incident Response Life Cycle are you actively working on removing the
malicious activity? - Answers Containment, Eradication, and Recovery Phase
In which phase of the NIST Incident Response Life Cycle do you document the security incident, review
the effectiveness of the incident handling process, and identify the necessary revisions to existing
security controls and practices? - Answers Post-Incident Activity Phase
Which network intelligence organization maintains a risk assessment tool that assigns a numeric score
to describe the severity of a vulnerability? - Answers Forum of Incident Response and Security Teams
(FIRST)
In the syslog severity level, what level would it be if the system is unusable? - Answers Level 0
(Emergency)
In the syslog severity level, what level would it be if conditions should be corrected immediately? -
Answers Level 1 (Alert)
In the syslog severity level, what level would it be if there's critical conditions? - Answers Level 2
(Critical)
In the syslog severity level, what level would it be if there's error conditions? - Answers Level 3 (Error)
In the syslog severity level, what level would it be if it may indicate an error will occur if action is not
taken? - Answers Level 4 (Warning)
In the syslog severity level, what level would it be if events that are unusual but are not error
conditions? - Answers Level 5 (Notice)