Modules 18-20 Flashcards
Which type of access control applies the strictest access control and is commonly used in military or mission critical applications?
Non-discretionary access control
discretionary access control (DAC)
attribute-based access control (ABAC)
mandatory access control (MAC)
mandatory access control (MAC)
How does BYOD change the way in which businesses implement networks?
BYOD requires organizations to purchase laptops rather than desktops.
BYOD provides flexibility in where and how users can access network resources.
BYOD users are responsible for their own network security, thus reducing the need for organizational security policies.
BYOD devices are more expensive than devices that are purchased by an organization.
BYOD provides flexibility in where and how users can access network resources.
In a defense-in-depth approach, which three options must be identified to effectively defend a network against attacks? (Choose three.)
total number of devices that attach to the wired and wireless network
assets that need protection
vulnerabilities in the system
location of attacker or attackers
past security breaches
threats to assets
assets that need protection
threats to assets
vulnerabilities in the system
Why is asset management a critical function of a growing organization against security threats?
It identifies the ever increasing attack surface to threats.
It allows for a build of a comprehensive AUP.
It serves to preserve an audit trail of all new purchases.
It prevents theft of older assets that are decommissioned.
It identifies the ever increasing attack surface to threats.
Which type of business policy establishes the rules of conduct and the responsibilities of employees and employers?
employee
data
company
security
company
What device would be used as the third line of defense in a defense-in-depth approach?
host
firewall
internal router
edge router
internal router
What is the first line of defense when an organization is using a defense-in-depth approach to network security?
edge router
firewall
proxy server
IPS
edge router
What is the primary function of the Center for Internet Security (CIS)?
- to maintain a list of common vulnerabilities and exposures (CVE) used by security organizations
- to provide a security news portal that aggregates the latest breaking news pertaining to alerts, exploits, and vulnerabilities
- to offer 24×7 cyberthreat warnings and advisories, vulnerability identification, and mitigation and incident responses
- to provide vendor-neutral education products and career services to industry professionals worldwide
to offer 24×7 cyberthreat warnings and advisories, vulnerability identification, and mitigation and incident responses
What is CybOX?
- It is a specification for an application layer protocol that allows the communication of CTI over HTTPS.
- It is a set of standardized schemata for specifying, capturing, characterizing, and communicating events and properties of network operations.
- It enables the real-time exchange of cyberthreat indicators between the U.S. Federal Government and the private sector.
- It is a catalog of known security threats called Common Vulnerabilities and Exposures (CVE) for publicly known cybersecurity vulnerabilities.
It is a set of standardized schemata for specifying, capturing, characterizing, and communicating events and properties of network operations.
What three goals does a BYOD security policy accomplish? (Choose three.)
- identify all malware signatures and synchronize them across corporate databases
- identify which employees can bring their own devices
- identify safeguards to put in place if a device is compromised
- identify and prevent all heuristic virus signatures
- identify a list of websites that users are not permitted to access
- describe the rights to access and activities permitted to security personnel on the device
identify which employees can bring their own devices
identify safeguards to put in place if a device is compromised
describe the rights to access and activities permitted to security personnel on the device
When designing a prototype network for a new server farm, a network designer chooses to use redundant links to connect to the rest of the network. Which business goal will be addressed by this choice?
availability
manageability
security
scalability
availability
When a security audit is performed at a company, the auditor reports that new users have access to network resources beyond their normal job roles. Additionally, users who move to different positions retain their prior permissions. What kind of violation is occurring?
least privilege
network policy
password
audit
least privilege
Which component of the zero trust security model focuses on secure access when an API, a microservice, or a container is accessing a database within an application?
workflow
workforce
workload
workplace
workload
Which two options are security best practices that help mitigate BYOD risks? (Choose two.)
- Use paint that reflects wireless signals and glass that prevents the signals from going outside the building.
- Keep the device OS and software updated.
- Only allow devices that have been approved by the corporate IT team.
- Only turn on Wi-Fi when using the wireless network.
- Decrease the wireless antenna gain level.
- Use wireless MAC address filtering.
Keep the device OS and software updated.
Only turn on Wi-Fi when using the wireless network
What is the purpose of mobile device management (MDM) software?
It is used to create a security policy.
It is used to implement security policies, setting, and software configurations on mobile devices.
It is used to identify potential mobile device vulnerabilities.
It is used by threat actors to penetrate the system.
It is used to implement security policies, setting, and software configurations on mobile devices.