MISY 5325 QUESTIONS AND ANSWERS SET A+
✔✔From the point of view of cybersecurity incident response, examples of incidents
include ALL EXCEPT:
exposure of or modification of legally protected data
exposure of or modification of public data
unauthorized access to intellectual property
disruption of internal or external services - ✔✔exposure of or modification of public data
✔✔Key incident management personnel include ALL EXCEPT:
incident response coordinators
designated incident handlers
incident response team members
internal advisors - ✔✔internal advisors
✔✔__________ forensic evidence is information in digital form found on a wide range of
endpoint, server, and network devices.
Digital
Cybersecurity
All
Current - ✔✔Digital
✔✔A(n) __________ is any observable occurrence in a system or network.
incident
policy
event
notification - ✔✔event
✔✔A __________ is when the intrusion detection device identifies an activity as
acceptable behavior and the activity is actually acceptable.
, false positive
false negative
true positive
true negative - ✔✔true negative
✔✔From the point of view of cybersecurity incident response, examples of incidents
include ALL EXCEPT: - ✔✔Exposure of or modification of public data
✔✔Key incident management personnel include ALL EXCEPT: - ✔✔Internal advisors
✔✔__________ forensic evidence can take many forms, depending on the conditions of
each case and the devices from which the evidence was collected. - ✔✔Cybersecurity
✔✔Incident response procedures are detailed steps needed to implement the plan.
True
False - ✔✔True
✔✔A __________ is a broad term that describes a situation in which a security device
triggers an alarm but there is no malicious activity or an actual attack taking place. -
✔✔False positive
✔✔A __________ is a successful identification of a security attack or a malicious event.
- ✔✔True positive
✔✔Tasks assigned to the incident response team (IRT) include all BUT the following: -
✔✔Compliance with upper management policies
✔✔Establishing a Computer Security Incident Response Team (CSIRT) involves the
following steps EXCEPT: - ✔✔Determining whether the team will be CSIRT
✔✔A(n) __________ cage is often built out of a mesh of conducting material that
prevents electromagnetic energy from entering into or escaping from the cage. -
✔✔Faraday
✔✔Declaration of an incident should trigger a voluntary response process.
True
False - ✔✔False
✔✔Forensic tools and techniques are often used to find the root cause of an incident or
to uncover facts.
✔✔From the point of view of cybersecurity incident response, examples of incidents
include ALL EXCEPT:
exposure of or modification of legally protected data
exposure of or modification of public data
unauthorized access to intellectual property
disruption of internal or external services - ✔✔exposure of or modification of public data
✔✔Key incident management personnel include ALL EXCEPT:
incident response coordinators
designated incident handlers
incident response team members
internal advisors - ✔✔internal advisors
✔✔__________ forensic evidence is information in digital form found on a wide range of
endpoint, server, and network devices.
Digital
Cybersecurity
All
Current - ✔✔Digital
✔✔A(n) __________ is any observable occurrence in a system or network.
incident
policy
event
notification - ✔✔event
✔✔A __________ is when the intrusion detection device identifies an activity as
acceptable behavior and the activity is actually acceptable.
, false positive
false negative
true positive
true negative - ✔✔true negative
✔✔From the point of view of cybersecurity incident response, examples of incidents
include ALL EXCEPT: - ✔✔Exposure of or modification of public data
✔✔Key incident management personnel include ALL EXCEPT: - ✔✔Internal advisors
✔✔__________ forensic evidence can take many forms, depending on the conditions of
each case and the devices from which the evidence was collected. - ✔✔Cybersecurity
✔✔Incident response procedures are detailed steps needed to implement the plan.
True
False - ✔✔True
✔✔A __________ is a broad term that describes a situation in which a security device
triggers an alarm but there is no malicious activity or an actual attack taking place. -
✔✔False positive
✔✔A __________ is a successful identification of a security attack or a malicious event.
- ✔✔True positive
✔✔Tasks assigned to the incident response team (IRT) include all BUT the following: -
✔✔Compliance with upper management policies
✔✔Establishing a Computer Security Incident Response Team (CSIRT) involves the
following steps EXCEPT: - ✔✔Determining whether the team will be CSIRT
✔✔A(n) __________ cage is often built out of a mesh of conducting material that
prevents electromagnetic energy from entering into or escaping from the cage. -
✔✔Faraday
✔✔Declaration of an incident should trigger a voluntary response process.
True
False - ✔✔False
✔✔Forensic tools and techniques are often used to find the root cause of an incident or
to uncover facts.