ITN 260 MODULE 12,13 AND 15
REVIEW QUESTIONS AND
ANSWERS
Which of the following is typically a monthly discussion of a scenario conducted in an
informal and stress-free environment to evaluate an incident response plan?
a. Simulation
b. Incident Response Plan Evaluation (IRP-E)
c. Tabletop
d. Walkthrough - Answer-Tabletop
Ella wants to research an attack framework that incorporates adversary, infrastructure,
capability, and victim. Which of the following would she choose?
a. Cyber Kill Chain
b. Mitre ATT&CK
c. Basic-Advanced Incident (BAI) Framework
d. Diamond Model of Intrusion Analysis - Answer-Diamond Model of Intrusion Analysis
Blaise needs to create a document that is a linear-style checklist of required manual
steps and actions needed to successfully respond to a specific type of incident. What
does she need to create?
a. ARC Codebook
b. Runbook
c. Playbook
d. SIEM-book - Answer-Playbook
Which of the following should be performed in advance of an incident?
a. Isolation
b. Capture
c. Containment
d. Segmentation - Answer-Segmentation
What is a platform used to provide telephony, video, and web conferences that can
serve as an entry point to a threat actor?
a. SIP
b. IP voice
, c. Call manager
d. VoIP - Answer-Call Manager
Which of the following is NOT a problem associated with log management?
a. Different log formats
b. Multiple devices generating logs
c. Time-stamped log data
d. Large volume of log data - Answer-Time-stamped log data
Which tool is an open source utility for UNIX devices that includes content filtering?
a. nxlog
b. syslog
c. rsyslog
d. syslog-ng - Answer-syslog-ng
Which of the following is a packet sampling protocol that gives a statistical sample
instead of the actual flow of packets?
a. IPFIX
b. sFlow
c. NetFlow
d. journalctl - Answer-sFlow
Which of the following is the most fragile and should be captured first in a forensics
investigation?
a. Kernel statistics
b. CPU cache
c. ARP cache
d. RAM - Answer-CPU cache
Which of the following is a Linux utility that displays the contents of system memory?
a. memdump
b. WinHex
c. dd
d. Autopsy - Answer-Memdump
How is the Security Assertion Markup Language (SAML) used?
a. It is no longer used because it has been replaced by LDAP.
b. It is an authenticator in IEEE 802.1x.
c. It allows secure web domains to exchange user authentication and authorization
data.
REVIEW QUESTIONS AND
ANSWERS
Which of the following is typically a monthly discussion of a scenario conducted in an
informal and stress-free environment to evaluate an incident response plan?
a. Simulation
b. Incident Response Plan Evaluation (IRP-E)
c. Tabletop
d. Walkthrough - Answer-Tabletop
Ella wants to research an attack framework that incorporates adversary, infrastructure,
capability, and victim. Which of the following would she choose?
a. Cyber Kill Chain
b. Mitre ATT&CK
c. Basic-Advanced Incident (BAI) Framework
d. Diamond Model of Intrusion Analysis - Answer-Diamond Model of Intrusion Analysis
Blaise needs to create a document that is a linear-style checklist of required manual
steps and actions needed to successfully respond to a specific type of incident. What
does she need to create?
a. ARC Codebook
b. Runbook
c. Playbook
d. SIEM-book - Answer-Playbook
Which of the following should be performed in advance of an incident?
a. Isolation
b. Capture
c. Containment
d. Segmentation - Answer-Segmentation
What is a platform used to provide telephony, video, and web conferences that can
serve as an entry point to a threat actor?
a. SIP
b. IP voice
, c. Call manager
d. VoIP - Answer-Call Manager
Which of the following is NOT a problem associated with log management?
a. Different log formats
b. Multiple devices generating logs
c. Time-stamped log data
d. Large volume of log data - Answer-Time-stamped log data
Which tool is an open source utility for UNIX devices that includes content filtering?
a. nxlog
b. syslog
c. rsyslog
d. syslog-ng - Answer-syslog-ng
Which of the following is a packet sampling protocol that gives a statistical sample
instead of the actual flow of packets?
a. IPFIX
b. sFlow
c. NetFlow
d. journalctl - Answer-sFlow
Which of the following is the most fragile and should be captured first in a forensics
investigation?
a. Kernel statistics
b. CPU cache
c. ARP cache
d. RAM - Answer-CPU cache
Which of the following is a Linux utility that displays the contents of system memory?
a. memdump
b. WinHex
c. dd
d. Autopsy - Answer-Memdump
How is the Security Assertion Markup Language (SAML) used?
a. It is no longer used because it has been replaced by LDAP.
b. It is an authenticator in IEEE 802.1x.
c. It allows secure web domains to exchange user authentication and authorization
data.