1. Which of the following is an example of a technical security control?
A. Security awareness training
B. Firewalls
C. Incident response procedures
D. Security policies and procedures
Answer: B) Firewalls
Rationale: Technical security controls include hardware or software-
based security measures, such as firewalls, intrusion
detection/prevention systems (IDS/IPS), and encryption tools.
2. What should be the first step in an incident response plan when a
breach is detected?
A. Contain the incident to prevent further damage
B. Notify the public about the breach
C. Analyze the breach to determine its cause
D. Restore affected systems from backups
Answer: A) Contain the incident to prevent further damage
Rationale: Containing the incident immediately prevents further
damage and limits the spread of the breach, enabling the incident
response team to address the issue effectively.
,3. Which type of access control ensures that a user's access rights are
based on their job role or function?
A. Mandatory Access Control (MAC)
B. Discretionary Access Control (DAC)
C. Role-Based Access Control (RBAC)
D. Attribute-Based Access Control (ABAC)
Answer: C) Role-Based Access Control (RBAC)
Rationale: RBAC assigns access rights based on a user’s job role or
function, ensuring that users only have access to resources necessary
for their work.
4. Which type of malware is designed to gain unauthorized access to a
system and monitor user activities, often without the user’s knowledge?
A. Worm
B. Trojan horse
C. Rootkit
D. Ransomware
Answer: C) Rootkit
Rationale: A rootkit is a type of malware designed to hide its presence
on a system and provide unauthorized access, often allowing attackers
to monitor activities and steal information undetected.
, 5. What is the purpose of network traffic analysis in security
operations?
A. To identify and block malicious activity on the network
B. To encrypt all data in transit across the network
C. To ensure compliance with network security policies
D. To identify potential vulnerabilities in network devices
Answer: A) To identify and block malicious activity on the network
Rationale: Network traffic analysis helps identify suspicious or
malicious activity in network communications, enabling security teams
to block or mitigate potential threats.
6. In the context of security operations, what is the definition of
'resilience'?
A. The ability to withstand and recover from security breaches and
incidents
B. The ability to prevent all cyberattacks from occurring
C. The implementation of backup and disaster recovery strategies
D. The use of firewalls and antivirus software to protect systems
Answer: A) The ability to withstand and recover from security
breaches and incidents
Rationale: Resilience refers to the ability of an organization to recover
quickly and continue operating in the face of security incidents or
breaches.
A. Security awareness training
B. Firewalls
C. Incident response procedures
D. Security policies and procedures
Answer: B) Firewalls
Rationale: Technical security controls include hardware or software-
based security measures, such as firewalls, intrusion
detection/prevention systems (IDS/IPS), and encryption tools.
2. What should be the first step in an incident response plan when a
breach is detected?
A. Contain the incident to prevent further damage
B. Notify the public about the breach
C. Analyze the breach to determine its cause
D. Restore affected systems from backups
Answer: A) Contain the incident to prevent further damage
Rationale: Containing the incident immediately prevents further
damage and limits the spread of the breach, enabling the incident
response team to address the issue effectively.
,3. Which type of access control ensures that a user's access rights are
based on their job role or function?
A. Mandatory Access Control (MAC)
B. Discretionary Access Control (DAC)
C. Role-Based Access Control (RBAC)
D. Attribute-Based Access Control (ABAC)
Answer: C) Role-Based Access Control (RBAC)
Rationale: RBAC assigns access rights based on a user’s job role or
function, ensuring that users only have access to resources necessary
for their work.
4. Which type of malware is designed to gain unauthorized access to a
system and monitor user activities, often without the user’s knowledge?
A. Worm
B. Trojan horse
C. Rootkit
D. Ransomware
Answer: C) Rootkit
Rationale: A rootkit is a type of malware designed to hide its presence
on a system and provide unauthorized access, often allowing attackers
to monitor activities and steal information undetected.
, 5. What is the purpose of network traffic analysis in security
operations?
A. To identify and block malicious activity on the network
B. To encrypt all data in transit across the network
C. To ensure compliance with network security policies
D. To identify potential vulnerabilities in network devices
Answer: A) To identify and block malicious activity on the network
Rationale: Network traffic analysis helps identify suspicious or
malicious activity in network communications, enabling security teams
to block or mitigate potential threats.
6. In the context of security operations, what is the definition of
'resilience'?
A. The ability to withstand and recover from security breaches and
incidents
B. The ability to prevent all cyberattacks from occurring
C. The implementation of backup and disaster recovery strategies
D. The use of firewalls and antivirus software to protect systems
Answer: A) The ability to withstand and recover from security
breaches and incidents
Rationale: Resilience refers to the ability of an organization to recover
quickly and continue operating in the face of security incidents or
breaches.