MCQ Bank
How many individuals were affected in anthem insurance breach 2014?
- A) 76.6 million
- B) 78.8 million
- C) 75.5 milllion
- D) 86.6 million
Which best practices are to be followed for applying security patches?
- A) There should be a working backup
- B) All the updates are necessary to install
- C) All the updates are necessary to install and working backup
- D) A good change control procedure and working backup
Automated configuration monitoring tools should compliant with which protocol to streamline reporting?
- A) Cis
- B) Disa
- C) Fisma
- D) Scap
why security engineering is placed at layer 3 of transformation model?
- A) Its not very beneficial to implement so kept at the later stage
- B) Because it’s a low hanging fruit.
- C) Requires very less time and effort.
- D) Consists of complicated security activities which take more time and effort
What is the first step in running a policy compliance scan through qualys?
- A) Build a policy
- B) Add IP address to scan
- C) Configure authentication
- D) Configure scan settings
Anthem insurance breach 2014 was initiated through?
- A) Man in the middle attack
- B) Windows vulnerability
- C) Phishing email
- D) Sql injection attack
As per carneige mellon university computing consortium commercial software contains?
- A) 20 to 30 bugs for every 1000 lines of code
- B) 40 to 50 bugs for every 1000 lines of code
- C) 40 to 50 bugs for every 10,000 lines of code
- D) 20 to 30 bugs for every 10,000 lines of code
Continuous monitoring feature of QULAYS is very useful for?
- A) Scanning of web application
- B) Vulnerability management of assets
- C) Checking compliance of CIS benchmarks
- D) Watching critical changes
Which team tests the patches in test environment in vulnerability management process?
- A) Information security team
- B) IT operations team
- C) Risk & compliance team
- D) Business team
Which of the following modules are displayed on home screen of qualys trial version?
- A) Vulnerability management and policy compliance
- B) File integrity monitoring
- C) Threat protection
- D) Asset review and administration
How security of outsourced services can be evaluated?
- A) Spot security checks
- B) Ask for 3rd party security review
- C) Include outsourced scope in internal audit
- D) Vulnerability assessment and penetration testing
In an enterprise which software should be allowed to install and execute?
- A) Softwares displayed on notice board.
- B) Softwares included in white-list.
- C) Any freely available software.
- D) Only paid software.
What practice of VM scanning mostly organizations follow in our local market?
- A) Monthly scan and remediate
- B) Fortnightly scan and remediate
- C) Once a year or not at all
- D) Quarterly scan and remediate
Which screen is displayed immediately after login screen in NESSUS scanner?
- A) Scan screen
- B) Vulnerability management screen
- C) Policy compliance screen
- D) Dashboard
Which one of the following is considered the first step in a vulnerability scan?
- A) Port scanning
- B) Firewall detection
- C) TCP/UDP service delivery
- D) Checking if the remote host is alive
In an enterprise which softwares should be allowed to install and execute?
- A) Any freely available software
- B) Softwares displayed on notice board
- C) Only paid software
- D) Softwares included in whitelist
Which of the following policies NESSUS can scan for compliance?
- A) CIS benchmarks
- B) SEI guidelines
- C) NIST controls
- D) OWAPS top 10
Which of the following function is performed by IT operation team in vulnerability management process?
- A) Takes backup and downtime
- B) Run vulnerability scanner
- C) Share report with management
- D) Tracks remediation timeline
What feature set QUALYS scanner offers?
- A) Not scalable
- B) Cloud based service
- C) Quarterly subscription
- D) Cost effective
Which of the following statement is correct?
- A) NVD is superset of CVSS
- B) CVE is superset of NVD
- C) NVD is superset of CVE
- D) NVD is an open standard for assigning vulnerability impacts