1. In the context of incident response, what does the term 'root cause
analysis' refer to?
A. Identifying the attacker’s identity
B. Evaluating the success of the recovery efforts
C. Determining the underlying cause of the security incident
D. Monitoring affected systems after the incident
Answer: C) Determining the underlying cause of the security incident
Rationale: Root cause analysis involves identifying the fundamental
issue that led to the security incident, which helps in preventing similar
incidents in the future.
2. What is the primary goal of a Disaster Recovery (DR) plan in the
context of security operations?
A. To prevent security breaches from happening
B. To recover systems and data after an attack or disaster
C. To monitor ongoing security incidents in real time
D. To conduct regular vulnerability scans on critical systems
Answer: B) To recover systems and data after an attack or disaster
Rationale: A Disaster Recovery plan focuses on restoring systems and
data to normal operations after a disaster or attack, ensuring business
continuity.
,3. Which of the following is an example of a physical security control?
A. Antivirus software
B. Biometric access control systems
C. Firewalls
D. Data encryption
Answer: B) Biometric access control systems
Rationale: Physical security controls include measures to protect
physical access to assets, such as biometric access controls, locks, and
surveillance systems.
4. What does 'least privilege' mean in the context of security
operations?
A. Only allowing access to the most critical data and systems
B. Restricting users’ access to only the resources necessary for their
tasks
C. Allowing users to access all resources to improve efficiency
D. Granting full administrative rights to all employees
Answer: B) Restricting users’ access to only the resources necessary for
their tasks
Rationale: The principle of least privilege ensures that users are
granted the minimum level of access necessary to perform their job
functions, reducing the risk of accidental or malicious misuse of
resources.
, 5. In security operations, what is the primary function of a firewall?
A. To provide secure access to applications
B. To block unauthorized access to or from a network
C. To monitor network traffic for malware
D. To encrypt data in transit
Answer: B) To block unauthorized access to or from a network
Rationale: A firewall is a network security device designed to monitor
and control incoming and outgoing network traffic based on
predetermined security rules, thus blocking unauthorized access.
6. What is the main function of a vulnerability scanner?
A. To automatically patch vulnerabilities in systems
B. To identify potential weaknesses in systems and applications
C. To monitor network traffic for malicious activity
D. To block unauthorized users from accessing resources
Answer: B) To identify potential weaknesses in systems and
applications
Rationale: Vulnerability scanners are used to identify potential
vulnerabilities in systems, software, and networks, allowing
organizations to address them before they can be exploited.
analysis' refer to?
A. Identifying the attacker’s identity
B. Evaluating the success of the recovery efforts
C. Determining the underlying cause of the security incident
D. Monitoring affected systems after the incident
Answer: C) Determining the underlying cause of the security incident
Rationale: Root cause analysis involves identifying the fundamental
issue that led to the security incident, which helps in preventing similar
incidents in the future.
2. What is the primary goal of a Disaster Recovery (DR) plan in the
context of security operations?
A. To prevent security breaches from happening
B. To recover systems and data after an attack or disaster
C. To monitor ongoing security incidents in real time
D. To conduct regular vulnerability scans on critical systems
Answer: B) To recover systems and data after an attack or disaster
Rationale: A Disaster Recovery plan focuses on restoring systems and
data to normal operations after a disaster or attack, ensuring business
continuity.
,3. Which of the following is an example of a physical security control?
A. Antivirus software
B. Biometric access control systems
C. Firewalls
D. Data encryption
Answer: B) Biometric access control systems
Rationale: Physical security controls include measures to protect
physical access to assets, such as biometric access controls, locks, and
surveillance systems.
4. What does 'least privilege' mean in the context of security
operations?
A. Only allowing access to the most critical data and systems
B. Restricting users’ access to only the resources necessary for their
tasks
C. Allowing users to access all resources to improve efficiency
D. Granting full administrative rights to all employees
Answer: B) Restricting users’ access to only the resources necessary for
their tasks
Rationale: The principle of least privilege ensures that users are
granted the minimum level of access necessary to perform their job
functions, reducing the risk of accidental or malicious misuse of
resources.
, 5. In security operations, what is the primary function of a firewall?
A. To provide secure access to applications
B. To block unauthorized access to or from a network
C. To monitor network traffic for malware
D. To encrypt data in transit
Answer: B) To block unauthorized access to or from a network
Rationale: A firewall is a network security device designed to monitor
and control incoming and outgoing network traffic based on
predetermined security rules, thus blocking unauthorized access.
6. What is the main function of a vulnerability scanner?
A. To automatically patch vulnerabilities in systems
B. To identify potential weaknesses in systems and applications
C. To monitor network traffic for malicious activity
D. To block unauthorized users from accessing resources
Answer: B) To identify potential weaknesses in systems and
applications
Rationale: Vulnerability scanners are used to identify potential
vulnerabilities in systems, software, and networks, allowing
organizations to address them before they can be exploited.