(AVSE)
1. Which stage of the kill chain involves an adversary gathering information
about the target before launching an attack?
A. Delivery
B. Reconnaissance
C. Installation
D. Command & Control
Answer: B. Reconnaissance
Explanation: Reconnaissance is the initial phase where attackers collect information about
the target system to identify potential vulnerabilities.
2. In the kill chain model, which stage represents the point at which malware
is actually delivered to the target system?
A. Weaponization
B. Exploitation
C. Delivery
D. Action on Objectives
Answer: C. Delivery
Explanation: Delivery is the stage where the malicious payload is transmitted to the target,
whether via email, network delivery, or another vector.
3. What is the primary purpose of the kill chain model in cybersecurity?
A. To list all known malware families
B. To provide a framework for understanding attack phases and identifying detection
points
C. To automate threat remediation
D. To classify viruses based on their infection mechanisms
Answer: B. To provide a framework for understanding attack phases and identifying
detection points
Explanation: The kill chain model helps security professionals understand each phase of an
attack, making it easier to detect, disrupt, and mitigate threats at various stages.
4. Which phase of the kill chain is primarily concerned with exploiting a
vulnerability to gain unauthorized access?
1
, ALIENVAULT CERTIFIED SECURITY ENGINEER
(AVSE)
A. Exploitation
B. Command & Control
C. Installation
D. Reconnaissance
Answer: A. Exploitation
Explanation: Exploitation is the phase in which the adversary takes advantage of a
vulnerability in the target system to execute malicious code or gain access.
5. In the context of AlienVault USM Anywhere, how are incident types
typically represented?
A. As a single generic alert for all incidents
B. As multiple events with associated context and severity levels
C. Only by the source IP address
D. By isolating each network packet
Answer: B. As multiple events with associated context and severity levels
Explanation: AlienVault USM Anywhere correlates various events, enriching them with
context such as severity, asset information, and incident type, to provide a comprehensive
view of the incident.
6. What distinguishes an “event” from an “alarm” in AlienVault terminology?
A. Events are high-priority alerts, while alarms are low-priority notifications
B. Events are raw logs and network activities; alarms are triggered based on correlation
and severity
C. Events and alarms are identical in every aspect
D. Alarms are generated only by the firewall, while events come from endpoints
Answer: B. Events are raw logs and network activities; alarms are triggered based on
correlation and severity
Explanation: In AlienVault, events represent the raw data generated by systems. Alarms are
produced when these events match certain conditions or correlation rules, indicating a
potential security incident.
7. Which of the following best describes the term “triage” in the context of
alarm management?
2
, ALIENVAULT CERTIFIED SECURITY ENGINEER
(AVSE)
A. Discarding alarms that are not important
B. Evaluating and categorizing alarms based on urgency and impact
C. Automatically resolving all alarms
D. Logging alarms for future reference without further action
Answer: B. Evaluating and categorizing alarms based on urgency and impact
Explanation: Triage involves reviewing alarms to determine which ones require immediate
action, ensuring that resources are focused on the most critical threats.
8. What is a key factor in prioritizing alarms during the incident response
process?
A. The color of the user interface
B. The geographic location of the incident
C. The severity level assigned through correlation rules and asset criticality
D. The time of day the alarm was generated
Answer: C. The severity level assigned through correlation rules and asset criticality
Explanation: Prioritization is often based on factors such as the severity of the threat, the
criticality of the affected asset, and contextual information provided by correlation rules.
9. In AlienVault USM Anywhere, which component is primarily responsible
for generating alarms from incoming events?
A. The firewall
B. The correlation engine
C. The endpoint agent
D. The database
Answer: B. The correlation engine
Explanation: The correlation engine analyzes events from various sources and applies rules
to determine if the pattern of activity constitutes a security alarm.
10. During which kill chain phase does an adversary establish communication
with a compromised system for remote control?
A. Reconnaissance
B. Delivery
C. Command & Control
D. Exploitation
3
, ALIENVAULT CERTIFIED SECURITY ENGINEER
(AVSE)
Answer: C. Command & Control
Explanation: The Command & Control phase involves establishing a communication
channel between the attacker and the compromised system to manage the attack remotely.
11. How does AlienVault USM Anywhere help in differentiating false positives
from true security incidents?
A. By using color-coded alerts
B. Through event correlation and contextual enrichment
C. By relying solely on user input
D. Through random sampling of events
Answer: B. Through event correlation and contextual enrichment
Explanation: The platform correlates events across multiple sources and adds context (such
as asset information and threat intelligence) to help distinguish between benign activities and
true incidents.
12. Which kill chain stage typically involves the installation of malware on the
target system?
A. Weaponization
B. Exploitation
C. Installation
D. Action on Objectives
Answer: C. Installation
Explanation: The installation stage is when the adversary places the malicious code or
payload on the target system, ensuring that they have a foothold in the environment.
13. In the context of incident types in AlienVault USM Anywhere, what is a
“true positive”?
A. An alarm that incorrectly identifies benign activity as malicious
B. An alarm that correctly identifies a security incident
C. An event with no relevance
D. A false alarm that is later discarded
Answer: B. An alarm that correctly identifies a security incident
Explanation: A true positive alarm accurately reflects a genuine security incident, allowing
responders to take appropriate action.
4