CSX CYBERSECURITY
FUNDAMENTALS:
COMPREHENSIVE VERIFIED
PRACTICE QUESTIONS AND
CORRECT ANSWERS FOR
GRADE A+
According to the NIST framework, which of the following are considered key functions
necessary for the protection of digital assets?
Protecting information assets by addressing threats to information that is processed,
stored or transported by interworked information systems - VERIFIED ANSWERS-The
best definition for cybersecurity?
Cybersecurity management - VERIFIED ANSWERS-Cybersecurity role that is charged
with the duty of managing incidents and remediation?
risk to an organization's digital assets. - VERIFIED ANSWERS-The core duty of
cybersecurity is to identify, respond and manage
is anything capable of acting against an asset in a manner that can cause harm. -
VERIFIED ANSWERS-A threat
is something of value worth protecting. - VERIFIED ANSWERS-A asset
is a weakness in the design, implementation, operation or internal controls in a process
that could be exploited to violate the system security - VERIFIED ANSWERS-A
vulnerability
attack vector - VERIFIED ANSWERS-The path or route used to gain access to the
target asset is known as a
payload - VERIFIED ANSWERS-In an attack, the container that delivers the exploit to
the target is called
communicate required and prohibited activities and behaviors. - VERIFIED ANSWERS-
Policies
1|Page
,CSX CYBERSECURITY FUNDAMENTALS
is a class of malware that hides the existence of other malware by modifying the
underlying operating system. - VERIFIED ANSWERS-Rootkit
provide details on how to comply with policies and standards. - VERIFIED ANSWERS-
Procedures
contain step-by-step instructions to carry out procedures. - VERIFIED ANSWERS-
Guidelines
also called malicious code, is software designed to gain access to targeted computer
systems, steal information or disrupt computer operations. - VERIFIED ANSWERS-
Malware
are used to interpret policies in specific situations. - VERIFIED ANSWERS-Standards
are solutions to software programming and coding errors. - VERIFIED ANSWERS-
Patches
includes many components such as directory services, authentication and authorization
services, and user management capabilities such as provisioning and deprovisioning. -
VERIFIED ANSWERS-Identity Management
Detect and block traffic from infected internal end points, Eliminate threats such as
email spam, viruses and worms, Control user traffic bound toward the Internet, Monitor
and detect network ports for rogue activity. - VERIFIED ANSWERS-The Internet
perimeter should
ensures that data are transferred reliably in the correct sequence - VERIFIED
ANSWERS-Transport layer of the OSI
coordinates and manages user connections - VERIFIED ANSWERS-Session layer of
the OSI
Encryption is an essential but incomplete form of access control - VERIFIED
ANSWERS-best states the role of encryption within an overall cybersecurity program
Asset value, criticality, reliability of each control and degree of exposure. - VERIFIED
ANSWERS-The number and types of layers needed for defense in depth are a function
of
Least privilege or access control - VERIFIED ANSWERS-System hardening should
implement the principle of
Accounting management, Fault management, Performance management, Security
management - VERIFIED ANSWERS-Which of the following are considered functional
areas of network management as defined by ISO?
2|Page
, CSX CYBERSECURITY FUNDAMENTALS
Multiple guests coexisting on the same server in isolation of one another - VERIFIED
ANSWERS-Virtualization involves
Maintaining an asset inventory. - VERIFIED ANSWERS-Vulnerability management
begins with an understanding of cybersecurity assets and their locations, which can be
accomplished by
Preparation, Detection and analysis, Investigation, Mitigation and recovery, Postincident
analysis - VERIFIED ANSWERS-Arrange the steps of the incident response process
into the correct order
Containment - VERIFIED ANSWERS-Which element of an incident response plan
involves obtaining and preserving evidence
Who had access to the evidence, in chronological order, Proof that the analysis is
based on copies identical to the original evidence, The procedures followed in working
with the evidence - VERIFIED ANSWERS-Select three. The chain of custody contains
information regarding
"violation or imminent threat of violation of computer security policies, acceptable use
policies, or standard security practices." - VERIFIED ANSWERS-NIST defines a Threat
as a
The estimated probability of the identified threats actually occurring, The efficiency and
effectiveness of existing risk mitigation controls, A list of potential vulnerabilities,
dangers and/or threats. - VERIFIED ANSWERS-Select all that apply. A business impact
analysis (BIA) should identify
is defined as "a model for enabling convenient, on-demand network access to a shared
pool of configurable resources (e.g., networks, servers, storage, applications and
services) that can be rapidly provisioned and released with minimal management or
service provider interaction - VERIFIED ANSWERS-Cloud computing
APTs typically originate from sources such as organized crime groups, activists or
governments, APTs use obfuscation techniques that help them remain undiscovered for
months or even years, APTs are often long-term, multi-phase projects with a focus on
reconnaissance - VERIFIED ANSWERS-Select all that apply. Which of the following
statements about advanced persistent threats (APTs) are true?
The reorientation of technologies and services designed around the individual end user.
- VERIFIED ANSWERS-Smart devices, BYOD strategies and freely available
applications and services are all examples of:
- cloud computing
- social media
3|Page