MCQ Bank
Which policy is recommended by data protection control of cis for mobile devices usage in an organization?
- A) Hard drive of mobile devices should be encrypted
- B) Employees should use only personal mobile devices
- C) Mobile devices should not be allowed
- D) Mobile devices are allowed for higher management only
While implementing the 4-layer security transformation model.
- A) It is suggested to have a high level and minimal (concise) policy in place
- B) There should be absolutely no policy in place
- C) It will be challenging to find suitable and trained security resources
- D) Policies and procedures are not at all required
Automated tools should be used to verify and compare the network devices configuration with.
- A) Some 3rd party recommended configuration
- B) Approved security configuration
- C) Default security configuration released by vendor
- D) Latest security configuration released by vendor
Boundary defense controls comes under which category of cis critical controls?
- A) Organizational controls
- B) Foundational controls
- C) Advanced controls
- D) Basic controls
After getting vulnerability scanning results patches should be applied to?
- A) Client machines only
- B) Network devices only
- C) All the systems throughout the organization
- D) Critical servers only
Wireless access control comes under which category of cis top 20 controls?
- A) Advanced
- B) Organizational
- C) Basic
- D) Foundational
The 4-layer security transformation model.
- A) Is adapted to solve Pakistan’s security posture challenges while being practical not to waste time on security governance in the absence of solid underlying security controls
- B) Will be rejected by the it dept as it takes too much hard work
- C) Takes too much time and effort to implement
- D) Is overkill
Which of the following tools can be used to enforce access controls to data?
- A) Security information and event management system
- B) File integrity monitoring solution
- C) Host-based data loss prevention (dlp)
- D) Network-based intrusion detection system
How can an authorized wireless access point connected to a wired network can be detected?
- A) Through network-based intrusion detection system
- B) Through host-based data loss prevention (dlp)
- C) Through file integrity monitoring solution
- D) Through wireless intrusion detection system
Generally speaking, security implementation in Pakistan is.
- A) Easy since lot of cost effective and trained resources are available in the market
- B) Robust and strong
- C) One generation behind that of it
- D) In line with it progress
In a large-sized security organization in Pakistan, it is likely the number of security staff will be.
- A) 1-5
- B) Over 50
- C) 30
- D) 5-10
As per cis framework what is the best practice to store logs generated from system?
- A) Store logs on the same machine which generates
- B) Store logs on a machine other than which generates
- C) Store logs on different dispersed locations
- D) Aggregate logs to a central management system
If a system in an organization gets compromised, how can we prevent an attacker to compromise the neighboring systems?
- A) Through antivirus
- B) Through system firewall
- C) Through network-based intrusion detection system(ips)
- D) Through network-based intrusion prevention system(ips)
Centrally managed anti-malware software should be used in an organization to.
- A) Continuously monitor and defend organization’s servers and workstations
- B) Continuously monitor and defend organization’s workstations
- C) Continuously monitor and defend organization’s edge routers
- D) Continuously monitor and defend organization’s servers
As per malware defense control why DNS query logging should be enabled?
- A) To lower the chance of spoofed or modified emails from valid email addresses
- B) analyze and block inbound email attachments with malicious behavior
- C) Continuously monitor and defend organization’s servers and workstations
- D) To detect host-name lookup for known malicious domains
How can an authorized wireless access point connected to a wired network can be detected and alerts can be generated?
- A) Through network-based intrusion detection system
- B) Through network vulnerability scanning tools
- C) Through file integrity monitoring solution
- D) Through host-based data loss prevention (dlp)
Each person with administrator account should be authorized by?
- A) Network administrator
- B) Help-desk team
- C) Senior executive
- D) System administrator
As per cis critical controls from how many minimum synchronized time resources all networks devices and servers should retrieve time?
- A) One
- B) Three
- C) As many as possible
- D) Two
Frequency of running automated vulnerability scanner against all systems on a network in an enterprise should be?
- A) Quarterly
- B) Monthly
- C) Weekly
- D) Fortnightly
In a medium-sized security organization in Pakistan, it is likely the number of security staff will be.
- A) 10-15
- B) 15-25
- C) 1-5
- D) 30+