MCQ Bank
Anthem insurance breach 2014 was initiated through?
- A) Sql injection attack
- B) Windows vulnerability
- C) Phishing email
- D) Man in the middle attack
In an enterprise which software should be allowed to install and execute?
- A) Softwares displayed on notice board.
- B) Any freely available software.
- C) Softwares included in white-list.
- D) Only paid software.
What should a system do whenever an administrator account is added or removed?
- A) Require super admin rights
- B) Should not allow
- C) Issue a log entry and alert
- D) Should block that account
Why cis recommends to configure monitoring system in an organization’s network?
- A) To record the network packets passing through the boundary
- B) To detect compromise of systems at organization’s network boundaries
- C) To block data loss through organization’s network boundaries
- D) To block malicious traffic at organization’s network boundaries
What should an organization do to control access to sensitive information on need-to-know basis?
- A) Locate all sensitive information on separate vlans
- B) Locate all sensitive information on single vlans
- C) Store all sensitive information on single server
- D) Store sensitive information on multiple servers
When a vulnerability scan is run and report is generated and shared with respective resources, which vulnerabilities they should fix on priority basis?
- A) Medium risk vulnerabilities
- B) Critical risk vulnerabilities
- C) High risk vulnerabilities
- D) Low risk vulnerabilities
From which type of systems URL requests should be logged in order to identify potentially malicious activity?
- A) On-site devices
- B) Mobile devices
- C) Off-site devices
- D) Each of the organization’s system
Which policy is recommended by data protection control of cis for mobile devices usage in an organization?
- A) Hard drive of mobile devices should be encrypted
- B) Employees should use only personal mobile devices
- C) Mobile devices should not be allowed
- D) Mobile devices are allowed for higher management only
While implementing the 4-layer security transformation model.
- A) It is suggested to have a high level and minimal (concise) policy in place
- B) There should be absolutely no policy in place
- C) It will be challenging to find suitable and trained security resources
- D) Policies and procedures are not at all required
Automated tools should be used to verify and compare the network devices configuration with.
- A) Some 3rd party recommended configuration
- B) Approved security configuration
- C) Default security configuration released by vendor
- D) Latest security configuration released by vendor
Boundary defense controls comes under which category of cis critical controls?
- A) Organizational controls
- B) Foundational controls
- C) Advanced controls
- D) Basic controls
After getting vulnerability scanning results patches should be applied to?
- A) Client machines only
- B) Network devices only
- C) All the systems throughout the organization
- D) Critical servers only
Wireless access control comes under which category of cis top 20 controls?
- A) Advanced
- B) Organizational
- C) Basic
- D) Foundational
The 4-layer security transformation model.
- A) Is adapted to solve Pakistan’s security posture challenges while being practical not to waste time on security governance in the absence of solid underlying security controls
- B) Will be rejected by the it dept as it takes too much hard work
- C) Takes too much time and effort to implement
- D) Is overkill
Which of the following tools can be used to enforce access controls to data?
- A) Security information and event management system
- B) File integrity monitoring solution
- C) Host-based data loss prevention (dlp)
- D) Network-based intrusion detection system
How can an authorized wireless access point connected to a wired network can be detected?
- A) Through network-based intrusion detection system
- B) Through host-based data loss prevention (dlp)
- C) Through file integrity monitoring solution
- D) Through wireless intrusion detection system
Generally speaking, security implementation in Pakistan is.
- A) Easy since lot of cost effective and trained resources are available in the market
- B) Robust and strong
- C) One generation behind that of it
- D) In line with it progress
In a large-sized security organization in Pakistan, it is likely the number of security staff will be.
- A) 1-5
- B) Over 50
- C) 30
- D) 5-10
As per cis framework what is the best practice to store logs generated from system?
- A) Store logs on the same machine which generates
- B) Store logs on a machine other than which generates
- C) Store logs on different dispersed locations
- D) Aggregate logs to a central management system
If a system in an organization gets compromised, how can we prevent an attacker to compromise the neighboring systems?
- A) Through antivirus
- B) Through system firewall
- C) Through network-based intrusion detection system(ips)
- D) Through network-based intrusion prevention system(ips)