Check answers here:
Modules 26 - 28: Analyzing Security Data Group Exam (Answers)
Quiz-summary
0 of 37 questions completed
Questions:
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
- 16
- 17
- 18
- 19
- 20
- 21
- 22
- 23
- 24
- 25
- 26
- 27
- 28
- 29
- 30
- 31
- 32
- 33
- 34
- 35
- 36
- 37
Information
Modules 26 - 28: Analyzing Security Data Group Exam - Test online
You have already completed the quiz before. Hence you can not start it again.
Quiz is loading...
You must sign in or sign up to start the quiz.
You have to finish following quiz, to start this quiz:
Results
0 of 37 questions answered correctly
Your time:
Time has elapsed
You have reached 0 of 0 points, (0)
| Average score |
|
| Your score |
|
Categories
- Not categorized 0%
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
- 16
- 17
- 18
- 19
- 20
- 21
- 22
- 23
- 24
- 25
- 26
- 27
- 28
- 29
- 30
- 31
- 32
- 33
- 34
- 35
- 36
- 37
- Answered
- Review
-
Question 1 of 37
1. Question
1 pointsMatch the intrusion event defined in the Diamond Model of intrusion to the description.Correct
Incorrect
-
Question 2 of 37
2. Question
1 pointsWhat two shared sources of information are included within the MITRE ATT&CK framework? (Choose two.)Correct
Incorrect
-
Question 3 of 37
3. Question
1 pointsWhat information is gathered by the CSIRT when determining the scope of a security incident?Correct
Incorrect
-
Question 4 of 37
4. Question
1 pointsAccording to NIST standards, which incident response stakeholder is responsible for coordinating an incident response with other stakeholders to minimize the damage of an incident?Correct
Incorrect
-
Question 5 of 37
5. Question
1 pointsAccording to NIST, which step in the digital forensics process involves drawing conclusions from data?Correct
Incorrect
-
Question 6 of 37
6. Question
1 pointsA cybersecurity analyst has been called to a crime scene that contains several technology items including a computer. Which technique will be used so that the information found on the computer can be used in court?Correct
Incorrect
-
Question 7 of 37
7. Question
1 pointsIn which phase of the NIST incident response life cycle is evidence gathered that can assist subsequent investigations by authorities?Correct
Incorrect
-
Question 8 of 37
8. Question
1 pointsWhen dealing with security threats and using the Cyber Kill Chain model, which two approaches can an organization use to block a potential back door creation? (Choose two.)Correct
Incorrect
-
Question 9 of 37
9. Question
1 pointsWhat is defined in the SOP of a computer security incident response capability (CSIRC)?Correct
Incorrect
-
Question 10 of 37
10. Question
1 pointsHow does an application program interact with the operating system?Correct
Incorrect
-
Question 11 of 37
11. Question
1 pointsWhich tool included in the Security Onion provides a visual interface to NSM data?Correct
Incorrect
-
Question 12 of 37
12. Question
1 pointsWhich tool included in the Security Onion includes the capability of designing custom dashboards?Correct
Incorrect
-
Question 13 of 37
13. Question
1 pointsHow is the hash value of files useful in network security investigations?Correct
Incorrect
-
Question 14 of 37
14. Question
1 pointsWhich technology is a major standard consisting of a pattern of symbols that describe data to be matched in a query?Correct
Incorrect
-
Question 15 of 37
15. Question
1 pointsWhich tool is a Security Onion integrated host-based intrusion detection system?Correct
Incorrect
-
Question 16 of 37
16. Question
1 pointsWhich term is used to describe the process of converting log entries into a common format?Correct
Incorrect
-
Question 17 of 37
17. Question
1 pointsWhat is the purpose for data normalization?Correct
Incorrect
-
Question 18 of 37
18. Question
1 pointsWhich personnel in a SOC is assigned the task of verifying whether an alert triggered by monitoring software represents a true security incident?Correct
Incorrect
-
Question 19 of 37
19. Question
1 pointsRefer to the exhibit. A security analyst is reviewing an alert message generated by Snort. What does the number 2100498 in the message indicate?
Correct
Incorrect
-
Question 20 of 37
20. Question
1 pointsWhat are security event logs commonly based on when sourced by traditional firewalls?Correct
Incorrect
-
Question 21 of 37
21. Question
1 pointsA threat actor has successfully breached the network firewall without being detected by the IDS system. What condition describes the lack of alert?Correct
Incorrect
-
Question 22 of 37
22. Question
1 pointsWhat information is contained in the options section of a Snort rule?Correct
Incorrect
-
Question 23 of 37
23. Question
1 pointsA network administrator is trying to download a valid file from an internal server. However, the process triggers an alert on a NMS tool. What condition describes this alert?Correct
Incorrect
-
Question 24 of 37
24. Question
1 pointsWhat is indicated by a Snort signature ID that is below 3464?Correct
Incorrect
-
Question 25 of 37
25. Question
1 pointsAfter a security monitoring tool identifies a malware attachment entering the network, what is the benefit of performing a retrospective analysis?Correct
Incorrect
-
Question 26 of 37
26. Question
1 pointsA threat actor collects information from web servers of an organization and searches for employee contact information. The information collected is further used to search personal information on the Internet. To which attack phase do these activities belong according to the Cyber Kill Chain model?Correct
Incorrect
-
Question 27 of 37
27. Question
1 pointsWhich HIDS is integrated into the Security Onion and uses rules to detect changes in host-based operating parameters caused by malware through system calls?Correct
Incorrect
-
Question 28 of 37
28. Question
1 pointsWhich type of events should be assigned to categories in Sguil?Correct
Incorrect
-
Question 29 of 37
29. Question
1 pointsA cybersecurity analyst is going to verify security alerts using the Security Onion. Which tool should the analyst visit first?Correct
Incorrect
-
Question 30 of 37
30. Question
1 pointsRefer to the exhibit. Which field in the Sguil application window indicates the priority of an event or set of correlated events?
Correct
Incorrect
-
Question 31 of 37
31. Question
1 pointsMatch the Snort rule source to the description.Correct
Incorrect
-
Question 32 of 37
32. Question
1 pointsWhat is the purpose for data reduction as it relates to NSM?Correct
Incorrect
-
Question 33 of 37
33. Question
1 pointsWhy would threat actors prefer to use a zero-day attack in the Cyber Kill Chain weaponization phase?Correct
Incorrect
-
Question 34 of 37
34. Question
1 pointsWhat is the objective the threat actor in establishing a two-way communication channel between the target system and a CnC infrastructure?Correct
Incorrect
-
Question 35 of 37
35. Question
1 pointsWhich meta-feature element in the Diamond Model describes information gained by the adversary?Correct
Incorrect
-
Question 36 of 37
36. Question
1 pointsIn which step of the NIST incident response process does the CSIRT perform an analysis to determine which networks, systems, or applications are affected; who or what originated the incident; and how the incident is occurring?Correct
Incorrect
-
Question 37 of 37
37. Question
1 pointsWhich classification indicates that an alert is verified as an actual security incident?Correct
Incorrect
