ITN 260 EXAM STUDY GUIDE
QUESTIONS WITH 100% CORRECT
ANSWERS
Where can you find metadata showing where a picture was taken?
A) EXIF data
B) IPFIX data
C) E-mail metadata
D) SIP CTL - Answer-A) EXIF data
Which of these is not associated with syslog files?
A) journalctl
B) NXLog
C) SIP CTL
D) IPFIX - Answer-D) IPFIX
Correlation does what with SIEM data?
A) Determines causes
B) Provides background contextual information
C) allows rule-based interpretation of data
D) All of the above - Answer-C) allows rule-based interpretation of data
What is one of the challenges of NetFlow data?
A) proprietary format
B) Excess data fields
C) record size
D) removing duplicate records along a path - Answer-D) removing duplicate records
along a path
What tool can be used to read system log data in Linux systems?
A) Any text editor
B) Journalctl
C) Web browser
D) protocol analyzer - Answer-B) Journalctl
Which of the following are issues that need to be determined as part of setting up a
SIEM solution? ( check all that apply)
A) Sensor placement
B) Log files and relevant fields
C) Desired alert conditions
D) DNS logging - Answer-A,B,C, & D
,You have been directed by upper management to block employees from accessing
Facebook from the corporate machines. Which would be the easier way to exercise this
control?
A) Application allow list
B) Application block list
C) DLP
D) Content filtering - Answer-D) Content filtering
Having an expired certificate is an example of what type of error?
A) Mobile device management
B) configuration
C) application whitelisting
D) content filter/URL filter - Answer-B) configuration
A system-focused set of predetermined automation steps is an example of what?
A) isolation
B) Runbook
C) playbook
D) firewall rules - Answer-B) Runbook
Your business application server sends data to partners using encrypted (Signed)
messages.. You hear from one of the partners that their messages have ceased
coming. What should you investigate?
A) Application whitelist
B) application blacklist
C) the playbook for the system
D) configuration settings of the process - Answer-D) configuration settings of the
process
You have kiosk-based machines in the lobby and scattered through the facility. They do
not require a login for guests to access certain items. what is the best way to protect
these machines from user introducing trojans?
A) Application allow list
B) application block list
C) data loss prevention
D) configuration settings of the process - Answer-A) Application allow list
To coordinate team activities during an incident response event, what is the best way to
communicate approved instructions?
A) Runbook
B) MDM solution
C) quarantine rule
D) playbook - Answer-D) playbook
Your security system has identified a specific executable as potentially dangerous.
What is the best way to handle the specific item that was identified?
, A) segmentation
B) quarantine
C) firewall rule
D) playbook - Answer-B) quarantine
Your company has merged with another company, and it uses a different release of
accounting software than your company does. How could you provision user machines
in accounting so they will not inadvertently run the incorrect version?
A) Application allow listing
B) isolation
C) configuration associate with the application
D) application block listing - Answer-D) application block listing
You wish to keep people from using the internal mobile network to play games on their
personal phones. What would be the best method of managing this?
A) MDM
B) application block list
C) content filter
D) segmentation - Answer-A) MDM
What is the primary purpose of a SOAR solution?
A) to collect and aggregate diverse security data
B) to analyze data for anomalies and to create alerts
C) To produce approved, detailed response plans with respect to given incident
response scenarios
D) to manage configuration changes on systems - Answer-C) To produce approved,
detailed response plans with respect to given incident response scenarios
Volatile information locations such as the RAM changes constantly, and data collection
should occur in the order of volatility or lifetime of the data. Order the following list from
most volatile ( which should be collected first) to least volatile.
A) Routing tables, ARP cache, Process tables, Kernel statistics
B) Memory (RAM)
C) CPU, cache, and register contents
D) Temporary file system/ swap space - Answer-C, A, B, D
A common data element needed later in the forensics process is an accurate system
time with respect to an accurate external time source. A record time offset is calculated
by measure system time with an external clock such as a Network Time Protocol (NTP)
server. Which of the following must be considered relative to obtaining a record time
offset?
A) the record time offset can be lost if the system is powered down, so it is best
collected while the system is still running.
B) the internal clock may not be recorded to the same level of accuracy, so conversions
may be necessary
QUESTIONS WITH 100% CORRECT
ANSWERS
Where can you find metadata showing where a picture was taken?
A) EXIF data
B) IPFIX data
C) E-mail metadata
D) SIP CTL - Answer-A) EXIF data
Which of these is not associated with syslog files?
A) journalctl
B) NXLog
C) SIP CTL
D) IPFIX - Answer-D) IPFIX
Correlation does what with SIEM data?
A) Determines causes
B) Provides background contextual information
C) allows rule-based interpretation of data
D) All of the above - Answer-C) allows rule-based interpretation of data
What is one of the challenges of NetFlow data?
A) proprietary format
B) Excess data fields
C) record size
D) removing duplicate records along a path - Answer-D) removing duplicate records
along a path
What tool can be used to read system log data in Linux systems?
A) Any text editor
B) Journalctl
C) Web browser
D) protocol analyzer - Answer-B) Journalctl
Which of the following are issues that need to be determined as part of setting up a
SIEM solution? ( check all that apply)
A) Sensor placement
B) Log files and relevant fields
C) Desired alert conditions
D) DNS logging - Answer-A,B,C, & D
,You have been directed by upper management to block employees from accessing
Facebook from the corporate machines. Which would be the easier way to exercise this
control?
A) Application allow list
B) Application block list
C) DLP
D) Content filtering - Answer-D) Content filtering
Having an expired certificate is an example of what type of error?
A) Mobile device management
B) configuration
C) application whitelisting
D) content filter/URL filter - Answer-B) configuration
A system-focused set of predetermined automation steps is an example of what?
A) isolation
B) Runbook
C) playbook
D) firewall rules - Answer-B) Runbook
Your business application server sends data to partners using encrypted (Signed)
messages.. You hear from one of the partners that their messages have ceased
coming. What should you investigate?
A) Application whitelist
B) application blacklist
C) the playbook for the system
D) configuration settings of the process - Answer-D) configuration settings of the
process
You have kiosk-based machines in the lobby and scattered through the facility. They do
not require a login for guests to access certain items. what is the best way to protect
these machines from user introducing trojans?
A) Application allow list
B) application block list
C) data loss prevention
D) configuration settings of the process - Answer-A) Application allow list
To coordinate team activities during an incident response event, what is the best way to
communicate approved instructions?
A) Runbook
B) MDM solution
C) quarantine rule
D) playbook - Answer-D) playbook
Your security system has identified a specific executable as potentially dangerous.
What is the best way to handle the specific item that was identified?
, A) segmentation
B) quarantine
C) firewall rule
D) playbook - Answer-B) quarantine
Your company has merged with another company, and it uses a different release of
accounting software than your company does. How could you provision user machines
in accounting so they will not inadvertently run the incorrect version?
A) Application allow listing
B) isolation
C) configuration associate with the application
D) application block listing - Answer-D) application block listing
You wish to keep people from using the internal mobile network to play games on their
personal phones. What would be the best method of managing this?
A) MDM
B) application block list
C) content filter
D) segmentation - Answer-A) MDM
What is the primary purpose of a SOAR solution?
A) to collect and aggregate diverse security data
B) to analyze data for anomalies and to create alerts
C) To produce approved, detailed response plans with respect to given incident
response scenarios
D) to manage configuration changes on systems - Answer-C) To produce approved,
detailed response plans with respect to given incident response scenarios
Volatile information locations such as the RAM changes constantly, and data collection
should occur in the order of volatility or lifetime of the data. Order the following list from
most volatile ( which should be collected first) to least volatile.
A) Routing tables, ARP cache, Process tables, Kernel statistics
B) Memory (RAM)
C) CPU, cache, and register contents
D) Temporary file system/ swap space - Answer-C, A, B, D
A common data element needed later in the forensics process is an accurate system
time with respect to an accurate external time source. A record time offset is calculated
by measure system time with an external clock such as a Network Time Protocol (NTP)
server. Which of the following must be considered relative to obtaining a record time
offset?
A) the record time offset can be lost if the system is powered down, so it is best
collected while the system is still running.
B) the internal clock may not be recorded to the same level of accuracy, so conversions
may be necessary