MCQ Bank
Which cloud storage should be allowed to use in organization as per cis?
- A) Private cloud storage
- B) Authorized cloud storage
- C) Public cloud storage
- D) Hybrid cloud storage
In a large-sized security organization (belonging to a large-sized organization), the following security functions are likely to be found.
- A) Security infrastructure and security operations
- B) Engineering, operations, governance, and frameworks/standards
- C) Technical security support, security engineers
- D) Operations and governance
If multi-factor authentication is not supported then user accounts shall be required to?
- A) Use passwords longer than 14 characters
- B) Use same password on all the systems
- C) Use default passwords
- D) Use short passwords which are easy to remember
According to this module, the main function of the ciso (in an organization where ciso is reporting to cio) is to conduct the following for the security program.
- A) Plan, build, and run
- B) Perform security testing and accreditation
- C) Performance management and progress review
- D) Review, monitor, and propose
Which of the following can be used to block malicious traffic on organization’s network boundaries?
- A) Network-based intrusion prevention (ips) system
- B) Host-based intrusion detection (ids) sensors
- C) Host-based intrusion prevention (ips) system
- D) Network-based intrusion detection (ids) sensors
Which of the following activity should be performed to test organizational readiness to identify and stop attacks or to respond quickly and effectively?
- A) Quarterly internal pen test
- B) Annually external pen test
- C) Quarterly external pen test
- D) Periodic red team exercise
What type of machine should network administrators use for administrative tasks?
- A) Email and browsing facility available
- B) Have internet access
- C) Isolated from organization’s primary network
- D) Used for composing documents
Which of the following system configuration management tool is used for Linux systems?
- A) Puppet
- B) Active directory
- C) Fim
- D) Cis cat pro
Security governance may be considered as.
- A) A parallel function to it governance
- B) An out-dated concept which is no longer practical
- C) A sub-function of the it governance framework
- D) A function lying above the it governance framework
As per cis which authentication protocols should be used by wireless networks?
- A) Which require bio-metrics for authentication
- B) Which require digital certificates for authentication
- C) Which require smart cards for authentication
- D) Which require mutual multi-factor authentication
As per limitation and control of network control of cis active ports, protocols and services should be associated to.
- A) All the assets in asset inventory
- B) Hardware assets in asset inventory
- C) Software assets in asset inventory
- D) Active directory domain
Why should we use scap validated vulnerability scanner?
- A) Because of excellent reporting feature
- B) Because it looks for both code-based and configuration-based vulnerabilities
- C) Because it looks for code-based vulnerabilities
- D) Because of in-depth scanning feature
In which format results of penetration testing should be documented?
- A) PDF format
- B) Machine readable standard
- C) Excel format
- D) XML format
As per cis critical security framework what is recommended for network boundaries of an organization?
- A) Deny communication over unauthorized TCP or UDP ports
- B) Deny communication over unauthorized TCP ports
- C) Deny communication with all open ports
- D) Deny communication over unauthorized UDP ports
In which mode should vulnerability scanning be performed?
- A) Dedicated mode
- B) Authenticated mode
- C) Un-authenticated mode
- D) Deep scan mode
Which of the following can be used to look for unusual attack mechanisms on organization’s network boundaries?
- A) Host-based intrusion prevention (ips) system
- B) Network-based intrusion prevention (ips) system
- C) Network-based intrusion detection (ids) sensors
- D) Host-based intrusion detection (ids) sensors
Before deploying any new devices in a networked environment what should be done with passwords?
- A) Remove the passwords
- B) Keep the default passwords
- C) Create very small passwords
- D) Change the default passwords
The dedicated machine used by administrators for administrative tasks should have following features.
- A) Isolated from organization’s primary network
- B) All routine operational functions can be performed on it
- C) Have internet access
- D) Email and browsing facility available
As per boundary defense control of cis what should be done with network traffic at proxy?
- A) Allow all the network traffic
- B) Block all the network traffic
- C) Use blacklist to allow access to sites without decrypting
- D) Decrypt all encrypted network traffic prior to analyzing the content
The main difference between security organization in a large-sized and medium sized organization is that the following is absent in a medium sized security organization.
- A) Security frameworks and standards
- B) Ciso
- C) Chief risk officer
- D) Steering committee