EPISODE · Jan 22, 2025 · 32 MIN
ISC2 CC Domain 5: Security Operations Exam Study Questions by Edward Henriquez
from Decoded: The Cybersecurity Podcast · host Edward Henriquez
Domain 5: Security Operations What is the first step in the incident response process?A. ContainmentB. Detection and identificationC. RecoveryD. EradicationAnswer: BWhat is the purpose of log analysis in security operations?A. Enhance system performanceB. Identify and respond to suspicious activitiesC. Encrypt dataD. Monitor user activityAnswer: BWhich of the following is a security incident?A. Failed login attemptB. Unauthorized access to sensitive filesC. Network scan from a trusted deviceD. Scheduled maintenanceAnswer: BWhat is the purpose of a Security Information and Event Management (SIEM) system?A. Detect malwareB. Centralize security monitoring and alertsC. Automate patchingD. Block loginsAnswer: BWhat does “false positive” mean in security monitoring?A. Actual threat detectedB. Threat blocked successfullyC. Benign activity mistaken as a threatD. Failed login attemptAnswer: CWhat is the primary purpose of vulnerability scanning?A. Identify unpatched systemsB. Block malicious IPsC. Encrypt communicationsD. Monitor bandwidthAnswer: AWhat is a common use case for a playbook in incident response?A. Automate tasksB. Guide teams through responseC. Configure firewall rulesD. Test vulnerabilitiesAnswer: BWhat is the purpose of data retention policies?A. Encrypt sensitive filesB. Define data storage durationC. Automate backupsD. Block unauthorized accessAnswer: BWhich type of malware locks users out until a ransom is paid?A. WormB. RansomwareC. TrojanD. SpywareAnswer: BWhat is the purpose of forensic analysis in security?A. Detect ongoing attacksB. Collect and analyze evidenceC. Enhance encryptionD. Automate scansAnswer: BWhich of the following prevents insider threats?A. Network segmentationB. Access monitoring and loggingC. Multi-factor authenticationD. EncryptionAnswer: BWhat is an important step in the post-incident process?A. Block all external connectionsB. Perform a root cause analysisC. Encrypt logsD. Restore accessAnswer: BWhich of the following is an advanced persistent threat (APT)?A. Phishing emailB. Long-term targeted attack by a skilled groupC. Malware via USB drivesD. Brute force attackAnswer: BWhat is a zero-day vulnerability?A. Exploited weakness before patch releaseB. Outdated system vulnerabilityC. Malware-infected systemD. Known weakness with no exploitAnswer: AWhat is the purpose of a sandbox in malware analysis?A. Isolate and observe suspicious programsB. Encrypt filesC. Block trafficD. Restore filesAnswer: AWhat is the role of a disaster recovery plan?A. Restore operations after disruptionB. Prevent phishing attacksC. Automate backupsD. Enforce complianceAnswer: AWhat is the purpose of a business impact analysis (BIA)?A. Identify critical functions and their loss impactB. Detect malware infectionsC. Test firewall efficiencyD. Test disaster plansAnswer: AWhich of the following is part of change management?A. Evaluate risks before changesB. Block unauthorized IPsC. Automate vulnerability scansD. Monitor physical accessAnswer: AWhat is the purpose of least privilege in access control?A. Minimize user/system permissionsB. Encrypt dataC. Maximize productivityD. Improve password complexityAnswer: AWhat does a data loss prevention (DLP) solution do?A. Prevents sensitive data from unauthorized access/transmissionB. Encrypts all network trafficC. Blocks malicious email attachmentsD. Restores deleted filesAnswer: APatreon Support:https://www.patreon.com/DecodedPodcast
Embed this episode
NOW PLAYING
ISC2 CC Domain 5: Security Operations Exam Study Questions by Edward Henriquez
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.