Questions with accurate answers
A computer Risk Policy is a set of ideas to be implemented to overcome
the risk associated with computer security incidents. Identify the
procedure that is NOT part of the computer risk policy?
Ans✓✓✓Procedure for the ongoing training of employees authorized to
access the system
A distributed Denial of Service (DDoS) attack is a more common type
of DoS Attack, where a single system is targeted by a large number of
infected machines over the Internet. In a DDoS attack, attackers first
infect multiple systems which are known as: Ans✓✓✓Zombies
A threat source does not present a risk if NO vulnerability that can be
exercised for a particular threat source. Identify the step in which
different threat sources are defined: Ans✓✓✓Threat identification
A US Federal agency network was the target of a DoS attack that
prevented and impaired the normal authorized functionality of the
networks. According to agency's reporting timeframe guidelines, this
incident should be reported within two (2) HOURS of
discovery/detection if the successful attack is still ongoing and the
agency is unable to successfully mitigate the activity. Which incident
category of the US Federal Agency does this incident belong to?
Ans✓✓✓CAT 2
Abel, the IH&R team lead at a financial organization, was tasked with
investigating a security incident that occurred on the organization's web
,server. During the investigation, he classified incidents based on their
impact on the organizational assets and prioritized them as critical
incidents.
Which of the following OWASP best practices did Abel adopt in the
above scenario? Ans✓✓✓Triage and mitigation
According to MITRE ATT&CK framework, in which of the following
phases do attackers gather information both actively and passively about
the target system or network? Ans✓✓✓Reconnaissance
According to OWASP best practices, which of the following is a
significant step in restoring services or materials that have been affected
during an incident? Ans✓✓✓Recovery
According to the MITRE ATT&CK framework, identify the phase in
which attackers gain primary control to the target network by exploiting
vulnerabilities. Ans✓✓✓Initial Access
Adam, an incident handler, was tasked with performing live system
analysis on a suspected Windows machine. Through the preliminary
analysis, Adam determined that the malware is accessing a malicious
port. To further monitor and analyze the malware activities, he
employed a port monitoring tool that shows detailed listings of all the
connection endpoints on the system.
,Identify the tool employed by Adam in the above scenario.
Ans✓✓✓TCPView
Alex, an IH&R team member, was attempting to prevent malware
infections from spreading through a malicious file. Therefore, he
completely deleted the malicious file and changed the server
authentication credentials to sanitize the system before restoring it.
Which of the following RE&CT framework phases was Alex performing
in the above scenario? Ans✓✓✓Eradication
Alice, a software professional browsing the official website of an
advertising company, saw a message revealing important information
about the database associated with the website. Using this information,
Alice can perform a code-injection attack on the website and manipulate
the application components.
Identify the vulnerability identified by Alice in the above scenario to
access the database. Ans✓✓✓Errors
An audit trail policy collects all audit trails such as series of records of
computer events, about an operating system, application or user
activities. Which of the following statements is NOT true for an audit
trail policy: Ans✓✓✓It helps calculating intangible losses to the
organization due to incident
, An IH&R team was attempting to handle a security incident that
occurred on the core server of a client organization. Subsequently, the
team immediately launched analysis, recovery, and patch management
tools to quickly mitigate the incident and recover the server to its pre-
incident state.
Identify the OODA loop phase performed by the IH&R team in the
above scenario. Ans✓✓✓Act
An incident is analyzed for its nature, intensity and its effects on the
network and systems. Which stage of the incident response and handling
process involves auditing the system and network log files?
Ans✓✓✓Identification
An incident recovery plan is a statement of actions that should be taken
before, during or after an incident. Identify which of the following is
NOT an objective of the incident recovery plan? Ans✓✓✓Creating new
business processes to maintain profitability after incident
An organization faced an information security incident where a
disgruntled employee passed sensitive access control information to a
competitor. The organization's incident response manager, upon
investigation, found that the incident must be handled within a few hours
on the same day to maintain business continuity and market
competitiveness. How would you categorize such information security
incident? Ans✓✓✓High level incident