MCQ Bank
Centrally managed anti-malware software should be used in an organization to.
- A) Continuously monitor and defend organization’s servers and workstations
- B) Continuously monitor and defend organization’s workstations
- C) Continuously monitor and defend organization’s edge routers
- D) Continuously monitor and defend organization’s servers
As per malware defense control why DNS query logging should be enabled?
- A) To lower the chance of spoofed or modified emails from valid email addresses
- B) analyze and block inbound email attachments with malicious behavior
- C) Continuously monitor and defend organization’s servers and workstations
- D) To detect host-name lookup for known malicious domains
How can an authorized wireless access point connected to a wired network can be detected and alerts can be generated?
- A) Through network-based intrusion detection system
- B) Through network vulnerability scanning tools
- C) Through file integrity monitoring solution
- D) Through host-based data loss prevention (dlp)
Each person with administrator account should be authorized by?
- A) Network administrator
- B) Help-desk team
- C) Senior executive
- D) System administrator
As per cis critical controls from how many minimum synchronized time resources all networks devices and servers should retrieve time?
- A) One
- B) Three
- C) As many as possible
- D) Two
Frequency of running automated vulnerability scanner against all systems on a network in an enterprise should be?
- A) Quarterly
- B) Monthly
- C) Weekly
- D) Fortnightly
In a medium-sized security organization in Pakistan, it is likely the number of security staff will be.
- A) 10-15
- B) 15-25
- C) 1-5
- D) 30+
Which cloud storage should be allowed to use in organization as per cis?
- A) Private cloud storage
- B) Authorized cloud storage
- C) Public cloud storage
- D) Hybrid cloud storage
In a large-sized security organization (belonging to a large-sized organization), the following security functions are likely to be found.
- A) Security infrastructure and security operations
- B) Engineering, operations, governance, and frameworks/standards
- C) Technical security support, security engineers
- D) Operations and governance
If multi-factor authentication is not supported then user accounts shall be required to?
- A) Use passwords longer than 14 characters
- B) Use same password on all the systems
- C) Use default passwords
- D) Use short passwords which are easy to remember
According to this module, the main function of the ciso (in an organization where ciso is reporting to cio) is to conduct the following for the security program.
- A) Plan, build, and run
- B) Perform security testing and accreditation
- C) Performance management and progress review
- D) Review, monitor, and propose
Which of the following can be used to block malicious traffic on organization’s network boundaries?
- A) Network-based intrusion prevention (ips) system
- B) Host-based intrusion detection (ids) sensors
- C) Host-based intrusion prevention (ips) system
- D) Network-based intrusion detection (ids) sensors
Which of the following activity should be performed to test organizational readiness to identify and stop attacks or to respond quickly and effectively?
- A) Quarterly internal pen test
- B) Annually external pen test
- C) Quarterly external pen test
- D) Periodic red team exercise
What type of machine should network administrators use for administrative tasks?
- A) Email and browsing facility available
- B) Have internet access
- C) Isolated from organization’s primary network
- D) Used for composing documents
Which of the following system configuration management tool is used for Linux systems?
- A) Puppet
- B) Active directory
- C) Fim
- D) Cis cat pro
Security governance may be considered as.
- A) A parallel function to it governance
- B) An out-dated concept which is no longer practical
- C) A sub-function of the it governance framework
- D) A function lying above the it governance framework
As per cis which authentication protocols should be used by wireless networks?
- A) Which require bio-metrics for authentication
- B) Which require digital certificates for authentication
- C) Which require smart cards for authentication
- D) Which require mutual multi-factor authentication
As per limitation and control of network control of cis active ports, protocols and services should be associated to.
- A) All the assets in asset inventory
- B) Hardware assets in asset inventory
- C) Software assets in asset inventory
- D) Active directory domain
Why should we use scap validated vulnerability scanner?
- A) Because of excellent reporting feature
- B) Because it looks for both code-based and configuration-based vulnerabilities
- C) Because it looks for code-based vulnerabilities
- D) Because of in-depth scanning feature
In which format results of penetration testing should be documented?
- A) PDF format
- B) Machine readable standard
- C) Excel format
- D) XML format