1. What should be included in a security monitoring strategy for an
organization's internal network?
A. Regular penetration testing
B. Continuous monitoring of network traffic for unusual patterns
C. Performing a risk assessment on an annual basis
D. Ensuring that data encryption is implemented across the network
Answer: B) Continuous monitoring of network traffic for unusual
patterns
Rationale: Continuous monitoring of network traffic helps detect
unusual patterns that could indicate a potential security threat or attack
on the internal network.
2. In which phase of the incident response lifecycle is evidence collected
and preserved?
A. Detection and Analysis
B. Containment, Eradication, and Recovery
C. Post-Incident Activity
D. Identification
Answer: A) Detection and Analysis
,Rationale: The collection and preservation of evidence occur during the
Detection and Analysis phase, where the incident is confirmed and
forensic data is gathered for further investigation.
3. What is the primary function of a security audit?
A. To assess the effectiveness of security policies and controls
B. To perform regular penetration testing
C. To monitor user activities in real time
D. To detect network-based attacks
Answer: A) To assess the effectiveness of security policies and controls
Rationale: A security audit evaluates an organization's security policies,
procedures, and controls to ensure they are effective and compliant
with industry standards and regulations
4. Which of the following is an example of a physical security control?
A. Antivirus software
B. Biometric access control systems
C. Firewalls
D. Data encryption
Answer: B) Biometric access control systems
Rationale: Physical security controls include measures to protect
physical access to assets, such as biometric access controls, locks, and
surveillance systems.
, 5. What is the main purpose of conducting a business impact analysis
(BIA)?
A. To assess the cost of cybersecurity tools and technologies
B. To identify the potential impact of a disaster on critical business
functions
C. To monitor network traffic for vulnerabilities
D. To test incident response procedures
Answer: B) To identify the potential impact of a disaster on critical
business functions
Rationale: A BIA helps organizations identify and prioritize business
functions, assess the potential impact of disruptions, and develop
strategies for maintaining essential operations during and after a
disaster.
6. What is the main objective of patch management in a security
operations program?
A. To reduce the likelihood of social engineering attacks
B. To close vulnerabilities in software and systems
C. To ensure data is encrypted during transmission
D. To control access to sensitive data
Answer: B) To close vulnerabilities in software and systems
organization's internal network?
A. Regular penetration testing
B. Continuous monitoring of network traffic for unusual patterns
C. Performing a risk assessment on an annual basis
D. Ensuring that data encryption is implemented across the network
Answer: B) Continuous monitoring of network traffic for unusual
patterns
Rationale: Continuous monitoring of network traffic helps detect
unusual patterns that could indicate a potential security threat or attack
on the internal network.
2. In which phase of the incident response lifecycle is evidence collected
and preserved?
A. Detection and Analysis
B. Containment, Eradication, and Recovery
C. Post-Incident Activity
D. Identification
Answer: A) Detection and Analysis
,Rationale: The collection and preservation of evidence occur during the
Detection and Analysis phase, where the incident is confirmed and
forensic data is gathered for further investigation.
3. What is the primary function of a security audit?
A. To assess the effectiveness of security policies and controls
B. To perform regular penetration testing
C. To monitor user activities in real time
D. To detect network-based attacks
Answer: A) To assess the effectiveness of security policies and controls
Rationale: A security audit evaluates an organization's security policies,
procedures, and controls to ensure they are effective and compliant
with industry standards and regulations
4. Which of the following is an example of a physical security control?
A. Antivirus software
B. Biometric access control systems
C. Firewalls
D. Data encryption
Answer: B) Biometric access control systems
Rationale: Physical security controls include measures to protect
physical access to assets, such as biometric access controls, locks, and
surveillance systems.
, 5. What is the main purpose of conducting a business impact analysis
(BIA)?
A. To assess the cost of cybersecurity tools and technologies
B. To identify the potential impact of a disaster on critical business
functions
C. To monitor network traffic for vulnerabilities
D. To test incident response procedures
Answer: B) To identify the potential impact of a disaster on critical
business functions
Rationale: A BIA helps organizations identify and prioritize business
functions, assess the potential impact of disruptions, and develop
strategies for maintaining essential operations during and after a
disaster.
6. What is the main objective of patch management in a security
operations program?
A. To reduce the likelihood of social engineering attacks
B. To close vulnerabilities in software and systems
C. To ensure data is encrypted during transmission
D. To control access to sensitive data
Answer: B) To close vulnerabilities in software and systems