Information Security Management Examination (SG) | Section A Attack Mitigation and Business Continuity 06
Problem 1
Which term refers to an attack that abuses relative paths and the like to reach files outside the published area?
View explanation
The answer is directory traversal, an attack that abuses relative paths and the like to reach files outside the published area.
Problem 2
Which term refers to an attack that writes data beyond the area reserved for it, aiming to cause abnormal behaviour or execute arbitrary code?
View explanation
The answer is buffer overflow, an attack that writes data beyond the area reserved for it, aiming to cause abnormal behaviour or execute arbitrary code.
Problem 3
Which term refers to a technique of compromising a subcontractor or a software supplier in order to reach their business partners?
View explanation
The answer is supply chain attack, a technique of compromising a subcontractor or a software supplier in order to reach their business partners.
Problem 4
Which term refers to an attack aimed at a particular organisation or individual, carried on persistently while gathering information about them?
View explanation
The answer is targeted attack, an attack aimed at a particular organisation or individual, carried on persistently while gathering information about them.
Problem 5
Which term refers to a mechanism that continuously monitors endpoint behaviour and supports the detection, investigation of and response to compromise?
View explanation
The answer is EDR, a mechanism that continuously monitors endpoint behaviour and supports the detection, investigation of and response to compromise.
Problem 6
Which term refers to a mechanism that aggregates logs from many devices and correlates them to detect security events?
View explanation
The answer is SIEM, a mechanism that aggregates logs from many devices and correlates them to detect security events.
Problem 7
Which term refers to a mechanism that links and automates incident response procedures and supports analysis and handling?
View explanation
The answer is SOAR, a mechanism that links and automates incident response procedures and supports analysis and handling.
Problem 8
Which term refers to a mechanism that identifies confidential information and prevents it being sent or taken outside improperly?
View explanation
The answer is DLP, a mechanism that identifies confidential information and prevents it being sent or taken outside improperly.
Problem 9
Which term refers to a mechanism for centrally managing the settings and applications of smartphones and the like, and wiping them if they are lost?
View explanation
The answer is MDM, a mechanism for centrally managing the settings and applications of smartphones and the like, and wiping them if they are lost.
Problem 10
Which term refers to a mechanism that gives visibility into how cloud services are used and mediates the application of policy?
View explanation
The answer is CASB, a mechanism that gives visibility into how cloud services are used and mediates the application of policy.
Problem 11
Which term refers to a mechanism that continuously evaluates the settings of a cloud environment and detects dangerous configurations?
View explanation
The answer is CSPM, a mechanism that continuously evaluates the settings of a cloud environment and detects dangerous configurations.
Problem 12
Which term refers to the activity of investigating, with tools and the like, whether known weaknesses are present in a system?
View explanation
The answer is vulnerability assessment, the activity of investigating, with tools and the like, whether known weaknesses are present in a system.
Problem 13
Which term refers to the activity of trying real attack techniques with permission to verify whether intrusion is possible and what the impact would be?
View explanation
The answer is penetration testing, the activity of trying real attack techniques with permission to verify whether intrusion is possible and what the impact would be.
Problem 14
Which term refers to a scheme for scoring the severity of a vulnerability on a common scale?
View explanation
The answer is CVSS, a scheme for scoring the severity of a vulnerability on a common scale.
Problem 15
Which term refers to the numbering scheme that identifies published vulnerabilities uniquely?
View explanation
The answer is CVE, the numbering scheme that identifies published vulnerabilities uniquely.
Problem 16
Which term refers to the team that gathers information from inside and outside the organisation and responds to security incidents?
View explanation
The answer is CSIRT, the team that gathers information from inside and outside the organisation and responds to security incidents.
Problem 17
Which term refers to the techniques and procedures for collecting and analysing devices and logs with care to preserve evidence?
View explanation
The answer is digital forensics, the techniques and procedures for collecting and analysing devices and logs with care to preserve evidence.
Problem 18
Which term refers to recording who handled evidence and when, so that its identity and integrity can be accounted for?
View explanation
The answer is chain of custody, recording who handled evidence and when, so that its identity and integrity can be accounted for.
Problem 19
Which term refers to the target time within which operations or systems are to be restored after a disaster?
View explanation
The answer is RTO, the target time within which operations or systems are to be restored after a disaster.
Problem 20
Which term refers to the target stating up to which point in time data is to be recovered after a failure?
View explanation
The answer is RPO, the target stating up to which point in time data is to be recovered after a failure.
Result
More sets in this exam
- Information Security Management Examination (SG) | Section A Security Fundamentals 01
- Information Security Management Examination (SG) | Section A Threats and Attack Techniques 02
- Information Security Management Examination (SG) | Section A Cryptography, Authentication and Controls 03
- Information Security Management Examination (SG) | Section A Security Management and Law 04
- Information Security Management Examination (SG) | Section A Risk and Access Management 05
- Information Security Management Examination (SG) | Section A Risk Treatment, Supplier, and Incident Management Questions 08