MCQ Bank
Which of the following are common vulnerability scanners?
- A) Forcepoint & redwolf
- B) Nessus & rapid7
- C) Openvas & qualys
- D) Nessus, rapid7, Openvas & qualys
What information we get from open TCP and UDP ports?
- A) Whether host is alive or not
- B) Which OS is running on the host
- C) Network details of the host
- D) Which services are running on host
Which subscription service model QUALYS offers?
- A) Quarterly subscription
- B) Monthly subscription
- C) Bi-annual subscription
- D) Annual subscription
Which of the following are considered cumulative and product specific?
- A) Hotfixes,Service packs
- B) Qfes,Hotfixes
- C) Service packs
- D) Security patches,Service packs
How many TCP and UDP ports are scanned in a default scan?
- A) No ports are scanned by default
- B) 1900 UDP ports and 180 TCP ports
- C) 65, 535 TCP ports
- D) 1900 TCP ports and 180 UDP ports
How security of outsourced services can be evaluated?
- A) Spot security checks
- B) Ask for 3rd party security review
- C) Include outsourced scope in internal audit
- D) Vulnerability assessment and penetration testing
In an enterprise which softwares should be allowed to install and execute?
- A) Any freely available software
- B) Softwares included in whitelist
- C) Only paid software
- D) Softwares displayed on notice board
Against which frameworks NESSUS scanner gives configuration auditing feature?
- A) CYBERSCOPE AND GLBA
- B) CIS and DISA
- C) FFIEC AND FISMA
- D) HIPAA AND HITECH
Which subscription service model QUALYS offers?
- A) Annual subscription
- B) Bi-annual subscription
- C) Quarterly subscription
- D) Monthly subscription
Which team tests the patches in test environment in vulnerability management process?
- A) IT operations team
- B) Information security team
- C) Business team
- D) Risk & compliance team
What practice of VM scanning mostly organizations follow in our local market?
- A) Quarterly scan and remediate
- B) Monthly scan and remediate
- C) Fortnightly scan and remediate
- D) Once a year or not at all
Which activities are carried out at stage 1 of transformation model?
- A) Apply CIS/DISA benchmarks
- B) Take stock of the assets and prioritize
- C) All of the given
- D) Establish a MSB
Which of the following function is performed by IT operation team in vulnerability management process?
- A) Share report with management
- B) Run vulnerability scanner
- C) Takes backup and downtime
- D) Tracks remediation timeline
Anthem insurance breach 2014 was initiated through?
- A) Sql injection attack
- B) Windows vulnerability
- C) Phishing email
- D) Man in the middle attack
In an enterprise which software should be allowed to install and execute?
- A) Softwares displayed on notice board.
- B) Any freely available software.
- C) Softwares included in white-list.
- D) Only paid software.
What should a system do whenever an administrator account is added or removed?
- A) Require super admin rights
- B) Should not allow
- C) Issue a log entry and alert
- D) Should block that account
Why cis recommends to configure monitoring system in an organization’s network?
- A) To record the network packets passing through the boundary
- B) To detect compromise of systems at organization’s network boundaries
- C) To block data loss through organization’s network boundaries
- D) To block malicious traffic at organization’s network boundaries
What should an organization do to control access to sensitive information on need-to-know basis?
- A) Locate all sensitive information on separate vlans
- B) Locate all sensitive information on single vlans
- C) Store all sensitive information on single server
- D) Store sensitive information on multiple servers
When a vulnerability scan is run and report is generated and shared with respective resources, which vulnerabilities they should fix on priority basis?
- A) Medium risk vulnerabilities
- B) Critical risk vulnerabilities
- C) High risk vulnerabilities
- D) Low risk vulnerabilities
From which type of systems URL requests should be logged in order to identify potentially malicious activity?
- A) On-site devices
- B) Mobile devices
- C) Off-site devices
- D) Each of the organization’s system