1. Which of the following is a key goal of incident containment during
a security breach?
A. To identify the attacker’s identity
B. To prevent the incident from spreading and causing further damage
C. To conduct a post-incident review
D. To recover lost data from backups
Answer: B) To prevent the incident from spreading and causing further
damage
Rationale: Containment is a critical step in limiting the scope of a
security breach, ensuring that it does not escalate further and cause
more widespread damage.
2. What is the primary function of a security audit?
A. To assess the effectiveness of security policies and controls
B. To perform regular penetration testing
C. To monitor user activities in real time
D. To detect network-based attacks
Answer: A) To assess the effectiveness of security policies and controls
Rationale: A security audit evaluates an organization's security policies,
procedures, and controls to ensure they are effective and compliant
with industry standards and regulations
,3. Which of the following tools is commonly used for continuous
monitoring of security events and logs?
A. Antivirus software
B. Security Information and Event Management (SIEM)
C. Network Intrusion Prevention System (IPS)
D. Web Application Firewall (WAF)
Answer: B) Security Information and Event Management (SIEM)
Rationale: SIEM systems are used for continuous monitoring and
analysis of security events, providing real-time alerts and insights to
help identify potential security threats.
4. What is the purpose of a Security Information and Event
Management (SIEM) system?
A. To create firewall rules
B. To log and analyze security-related data from various systems
C. To secure physical access to the data center
D. To implement encryption protocols
Answer: B) To log and analyze security-related data from various
systems
Rationale: SIEM systems aggregate and analyze data from a variety of
sources, such as firewalls, intrusion detection systems (IDS), and
servers, to provide security monitoring and event management.
, 5. Which of the following is a primary responsibility of a Security
Operations Center (SOC)?
A. Developing application security policies
B. Managing incident response and monitoring security alerts
C. Conducting vulnerability assessments
D. Encrypting organizational data
Answer: B) Managing incident response and monitoring security alerts
Rationale: A Security Operations Center (SOC) is primarily responsible
for continuously monitoring an organization's security environment,
managing incident responses, and analyzing security alerts to protect
the organization.
6. In security operations, what is the primary function of a firewall?
A. To provide secure access to applications
B. To block unauthorized access to or from a network
C. To monitor network traffic for malware
D. To encrypt data in transit
Answer: B) To block unauthorized access to or from a network
Rationale: A firewall is a network security device designed to monitor
and control incoming and outgoing network traffic based on
predetermined security rules, thus blocking unauthorized access.
a security breach?
A. To identify the attacker’s identity
B. To prevent the incident from spreading and causing further damage
C. To conduct a post-incident review
D. To recover lost data from backups
Answer: B) To prevent the incident from spreading and causing further
damage
Rationale: Containment is a critical step in limiting the scope of a
security breach, ensuring that it does not escalate further and cause
more widespread damage.
2. What is the primary function of a security audit?
A. To assess the effectiveness of security policies and controls
B. To perform regular penetration testing
C. To monitor user activities in real time
D. To detect network-based attacks
Answer: A) To assess the effectiveness of security policies and controls
Rationale: A security audit evaluates an organization's security policies,
procedures, and controls to ensure they are effective and compliant
with industry standards and regulations
,3. Which of the following tools is commonly used for continuous
monitoring of security events and logs?
A. Antivirus software
B. Security Information and Event Management (SIEM)
C. Network Intrusion Prevention System (IPS)
D. Web Application Firewall (WAF)
Answer: B) Security Information and Event Management (SIEM)
Rationale: SIEM systems are used for continuous monitoring and
analysis of security events, providing real-time alerts and insights to
help identify potential security threats.
4. What is the purpose of a Security Information and Event
Management (SIEM) system?
A. To create firewall rules
B. To log and analyze security-related data from various systems
C. To secure physical access to the data center
D. To implement encryption protocols
Answer: B) To log and analyze security-related data from various
systems
Rationale: SIEM systems aggregate and analyze data from a variety of
sources, such as firewalls, intrusion detection systems (IDS), and
servers, to provide security monitoring and event management.
, 5. Which of the following is a primary responsibility of a Security
Operations Center (SOC)?
A. Developing application security policies
B. Managing incident response and monitoring security alerts
C. Conducting vulnerability assessments
D. Encrypting organizational data
Answer: B) Managing incident response and monitoring security alerts
Rationale: A Security Operations Center (SOC) is primarily responsible
for continuously monitoring an organization's security environment,
managing incident responses, and analyzing security alerts to protect
the organization.
6. In security operations, what is the primary function of a firewall?
A. To provide secure access to applications
B. To block unauthorized access to or from a network
C. To monitor network traffic for malware
D. To encrypt data in transit
Answer: B) To block unauthorized access to or from a network
Rationale: A firewall is a network security device designed to monitor
and control incoming and outgoing network traffic based on
predetermined security rules, thus blocking unauthorized access.