1. In security operations, what is the primary function of a firewall?
A. To provide secure access to applications
B. To block unauthorized access to or from a network
C. To monitor network traffic for malware
D. To encrypt data in transit
Answer: B) To block unauthorized access to or from a network
Rationale: A firewall is a network security device designed to monitor
and control incoming and outgoing network traffic based on
predetermined security rules, thus blocking unauthorized access.
2. What is the role of a Digital Forensics team in the aftermath of a
security incident?
A. To restore systems from backups
B. To recover lost or stolen data
C. To identify the cause of the incident and preserve evidence for legal
purposes
D. To notify stakeholders about the incident
Answer: C) To identify the cause of the incident and preserve evidence
for legal purposes
,Rationale: Digital Forensics teams analyze the aftermath of an incident
to understand what happened, gather evidence, and ensure that legal
requirements are met for potential prosecution.
3. Which of the following best describes the concept of defense in
depth?
A. Using multiple layers of security controls to protect an asset
B. Encrypting data at rest to prevent unauthorized access
C. Monitoring the network for malicious traffic
D. Blocking all external network connections
Answer: A) Using multiple layers of security controls to protect an
asset
Rationale: Defense in depth involves applying multiple layers of
security controls to protect critical assets, ensuring that if one layer is
breached, others remain to provide protection.
4. What is the purpose of network segmentation in security operations?
A. To create backups of sensitive data
B. To isolate sensitive data and systems from less secure parts of the
network
C. To monitor and record user activity across the entire network
D. To encrypt traffic between different parts of the network
Answer: B) To isolate sensitive data and systems from less secure parts
of the network
, Rationale: Network segmentation helps limit access to sensitive data
and systems, ensuring that a breach in one area does not lead to the
compromise of the entire network.
5. What should be included in a security monitoring strategy for an
organization's internal network?
A. Regular penetration testing
B. Continuous monitoring of network traffic for unusual patterns
C. Performing a risk assessment on an annual basis
D. Ensuring that data encryption is implemented across the network
Answer: B) Continuous monitoring of network traffic for unusual
patterns
Rationale: Continuous monitoring of network traffic helps detect
unusual patterns that could indicate a potential security threat or attack
on the internal network.
6. What is the primary focus of a Business Continuity Plan (BCP)?
A. To monitor the effectiveness of security policies
B. To ensure essential business operations can continue during or after
a disaster
C. To prevent malware infections
D. To audit user access privileges
Answer: B) To ensure essential business operations can continue
during or after a disaster
A. To provide secure access to applications
B. To block unauthorized access to or from a network
C. To monitor network traffic for malware
D. To encrypt data in transit
Answer: B) To block unauthorized access to or from a network
Rationale: A firewall is a network security device designed to monitor
and control incoming and outgoing network traffic based on
predetermined security rules, thus blocking unauthorized access.
2. What is the role of a Digital Forensics team in the aftermath of a
security incident?
A. To restore systems from backups
B. To recover lost or stolen data
C. To identify the cause of the incident and preserve evidence for legal
purposes
D. To notify stakeholders about the incident
Answer: C) To identify the cause of the incident and preserve evidence
for legal purposes
,Rationale: Digital Forensics teams analyze the aftermath of an incident
to understand what happened, gather evidence, and ensure that legal
requirements are met for potential prosecution.
3. Which of the following best describes the concept of defense in
depth?
A. Using multiple layers of security controls to protect an asset
B. Encrypting data at rest to prevent unauthorized access
C. Monitoring the network for malicious traffic
D. Blocking all external network connections
Answer: A) Using multiple layers of security controls to protect an
asset
Rationale: Defense in depth involves applying multiple layers of
security controls to protect critical assets, ensuring that if one layer is
breached, others remain to provide protection.
4. What is the purpose of network segmentation in security operations?
A. To create backups of sensitive data
B. To isolate sensitive data and systems from less secure parts of the
network
C. To monitor and record user activity across the entire network
D. To encrypt traffic between different parts of the network
Answer: B) To isolate sensitive data and systems from less secure parts
of the network
, Rationale: Network segmentation helps limit access to sensitive data
and systems, ensuring that a breach in one area does not lead to the
compromise of the entire network.
5. What should be included in a security monitoring strategy for an
organization's internal network?
A. Regular penetration testing
B. Continuous monitoring of network traffic for unusual patterns
C. Performing a risk assessment on an annual basis
D. Ensuring that data encryption is implemented across the network
Answer: B) Continuous monitoring of network traffic for unusual
patterns
Rationale: Continuous monitoring of network traffic helps detect
unusual patterns that could indicate a potential security threat or attack
on the internal network.
6. What is the primary focus of a Business Continuity Plan (BCP)?
A. To monitor the effectiveness of security policies
B. To ensure essential business operations can continue during or after
a disaster
C. To prevent malware infections
D. To audit user access privileges
Answer: B) To ensure essential business operations can continue
during or after a disaster