WITH CORRECT ANSWERS(RATED
A+)
In which cloud computing service model does a provider's applications run on a
cloud infrastructure and the consumer does not manage or control the underlying
infrastructure? (Choose one.)
a) platform as a service (PaaS)
b) infrastructure as a service (IaaS)
c) software as a service (SaaS)
d) public cloud - ANSWER[c] software as a service (SaaS)
True or False. Business intelligence (BI) software consists of tools and techniques
used to surface large amounts of raw unstructured data to perform a variety of tasks
including data mining, event processing, and predictive analytics. - ANSWERTrue
True or False. The process in which end users find personal technology and apps
that are more powerful or capable, more convenient, less expensive, quicker to
install, and easier to use than enterprise IT solutions is known as consumerization. -
ANSWERTrue
True or False. An organization can be compliant with all applicable security and
privacy regulations for its industry, yet still not be secure. - ANSWERTrue
Fill in the Blank. The U.S. law that establishes national standards to protect
individuals' medical records and other health information is known as the
. - ANSWERHealth Insurance Portability and Accountability Act (HIPAA)
True or False. Most cyberattacks today are perpetrated by internal threat actors such
as malicious employees engaging in corporate espionage. - ANSWERFalse
True or False. The Cyber-Attack Lifecycle is a five-step process that an attacker
goes through to attack a network. - ANSWERFalse
Multiple Answer. List and describe the steps of the Cyber-Attack Lifecycle. -
ANSWERReconnaissance, Weaponization, Delivery, Exploitation, Installation,
Command and Control, Actions on the Objective
True or False. An attacker needs to succeed in executing only one step of the Cyber-
Attack Lifecycle to infiltrate a network, whereas a defender must "be right every time"
and break every step of the chain to prevent an attack. - ANSWERFalse
Multiple Choice. Which technique is not used to break the command-and- control
(C&C) phase of the Cyber-Attack Lifecycle? (Choose one.)
a) blocking outbound traffic to known malicious sites and IP addresses
b) DNS sinkholing and DNS poisoning
, c) vulnerability and patch management
d) all of the above - ANSWER[c] vulnerability and patch management
True or False. The key to breaking the Cyber-Attack Lifecycle during the Installation
phase is to implement network segmentation, a Zero Trust model, and granular
control of applications to limit or restrict an attacker's lateral movement within the
network. - ANSWERTrue
True or False. Network firewalls cannot completely protect hosts from zero- day
exploits. - ANSWERTrue
Fill in the Blank. _______________ exploits target unknown vulnerabilities in
operating system and application software on a host machine. - ANSWERZero-day
Multiple Choice. Which option describes malicious software or code that typically
takes control of, collects information from, or damages an infected endpoint?
(Choose one.)
a) exploit
b) malware
c) vulnerability
d) none of the above - ANSWER[b] malware
Fill in the Blank. The Data Link layer of the OSI model is further divided into these
two sublayers: _ and _. - ANSWERmedia access control (MAC), Logical Link Control
(LLC)
Multiple Choice. Which four layers comprise the TCP/IP model? (Choose four.)
a) Application
b) Transport
c) Physical
d) Internet
e) Network Access - ANSWER[a] Application, [b] Transport, [d] Internet, [e] Network
Access
Fill in the Blank. The process that wraps protocol information from the (OSI or
TCP/IP) layer immediately above in the data section of the layer immediately below
is known as ____. - ANSWERdata encapsulation
Multiple Choice. Which option is an important characteristic or capability of advanced
malware? (Choose one.)
a) distributed, fault-tolerant architecture
b) multi-functionality
c) hiding techniques such as polymorphism, metamorphism, and
obfuscation
d) all of the above - ANSWER[d] all of the above
True or False. A vulnerability is a small piece of software code, part of a malformed
data file, or a sequence (string) of commands created by an attacker to cause
unintended or unanticipated behavior in a system or software. - ANSWERFalse