Tag the questions with any skills you have. Your dashboard will track each student's mastery of each skill.
Give this quiz to my class
Q 1/60
Score 0
Which of the following describes the 'IG1' (Implementation Group 1) in the context of CIS Critical Security Controls v8?
30
Advanced Persistent Threat Defense
Essential Cyber Hygiene
Supply Chain Risk Management
Regulated Business Compliance
Q 2/60
Score 0
In CIS Controls v8, the transition from 'Inventory and Control of Hardware Assets' to 'Inventory and Control of Enterprise Assets' reflects what strategic shift?
30
Removing the requirement to track virtual machines to simplify audits
Replacing physical hardware inventory with software-only tracking
Focusing on the inclusion of cloud-based resources, portable devices, and IoT
Mandating that all assets be owned by the enterprise rather than employees
60 questions
Q.
Which of the following describes the 'IG1' (Implementation Group 1) in the context of CIS Critical Security Controls v8?
1
30 sec
Q.
In CIS Controls v8, the transition from 'Inventory and Control of Hardware Assets' to 'Inventory and Control of Enterprise Assets' reflects what strategic shift?
2
30 sec
Q.
Which CIS Control focuses on the processes and tools used to track, report, and correct security vulnerabilities by interpreting data from industry sources and scanning tools?
3
30 sec
Q.
Under CIS Control 4, 'Secure Configuration of Enterprise Assets and Software', what is the primary purpose of establishing and maintaining a secure configuration process?
4
30 sec
Q.
Which CIS Control emphasizes the management of the full lifecycle of certificates and keys to ensure that only authorized people and devices have access to system data and resources?
5
30 sec
Q.
Which CIS Control is specifically focused on the use of processes and tools to prevent or control the installation, spread, and execution of malicious applications, code, or scripts on enterprise assets?
6
30 sec
Q.
Which CIS Control focuses on establishing, implementing, and actively managing (tracking, reporting on, correcting) the network devices, in order to prevent attackers from exploiting vulnerable network services and access points?
7
30 sec
Q.
Which CIS Control emphasizes the necessity of developing a plan, defining roles, and conducting exercises to ensure that an organization can quickly discover an attack and then effectively contain the damage?
8
30 sec
Q.
Which CIS Control focuses on the use of processes and tools to collect, alert, and retain record traces of events to help detect, understand, or recover from an attack?
9
30 sec
Q.
Which CIS Control focuses on identifying, classifying, and disposing of sensitive data, as well as managing its encryption both at rest and in transit?
10
30 sec
Q.
According to CIS Control 9 (Email and Web Browser Powers), which of the following is considered a primary 'quick win' for reducing the risk of drive-by downloads and malicious browser extensions?
11
30 sec
Q.
To mitigate risks from malicious attachments and phishing links, CIS Control 9 recommends which strategy regarding URL filtering and blocking?
12
30 sec
Q.
Which of the following configuration settings is specifically recommended under CIS Control 9 (Email and Web Browser Protections) to prevent the automated execution of malicious code within a web browser?
13
30 sec
Q.
Regarding CIS Control 9, which authentication and security protocol is recommended for implementation on email servers to verify the sender's identity and prevent email spoofing?
14
30 sec
Q.
In the context of CIS Control 9, why is it recommended to implement a 'sandboxed' or 'isolated' browser environment for high-risk users?
15
30 sec
Q.
Under CIS Control 9 (Email and Web Browser Protections), what is the primary security objective of implementing 'Email Server Sandboxing' or 'Attachment Detonation' technology?
16
30 sec
Q.
Under CIS Control 9, what is the primary security benefit of implementing 'Network-Based URL Filtering' for all enterprise assets?
17
30 sec
Q.
Which of the following describes the CIS Control 9 recommendation regarding the use of 'Protective DNS' (PDNS) for email and web protection?
18
30 sec
Q.
Regarding CIS Control 9 (Email and Web Browser Protections), why is it recommended to restrict or 'block' unauthorized browser extensions across the enterprise?
19
30 sec
Q.
Which of the following describes a key CIS Control 9 safeguard for hardening the enterprise email infrastructure against link-based attacks?
20
30 sec
Q.
According to CIS Control 10 (Malware Defenses), what is the primary reason for enabling 'anti-exploitation' features such as Data Execution Prevention (DEP) or Address Space Layout Randomization (ASLR) at the operating system level?
21
30 sec
Q.
Under CIS Control 10 (Malware Defenses), which approach is recommended to prevent malware from executing via removable media such as USB drives?
22
30 sec
Q.
Which of the following describes a key requirement of CIS Control 10 (Malware Defenses) regarding the management of security software logs?
23
30 sec
Q.
In the context of CIS Control 10 (Malware Defenses), why is it critical to ensure that anti-malware software is configured to perform 'behavioral-based' monitoring in addition to 'signature-based' detection?
24
30 sec
Q.
Regarding CIS Control 10 (Malware Defenses), what is the importance of implementing 'DNS filtering' as a defensive measure?
25
30 sec
Q.
Under CIS Control 10 (Malware Defenses), specifically regarding Infrastructure Management, what is the primary benefit of utilizing 'sandboxing' for suspicious files?
26
30 sec
Q.
According to CIS Control 10 (Malware Defenses), how should organizations handle 'Auto-Run' and 'Auto-Play' features on operating systems?
27
30 sec
Q.
Under CIS Control 10 (Malware Defenses), specifically Safeguard 10.7, what is the purpose of implementing 'Anti-Exploit' features such as DEP, ASLR, and SEHOP?
28
30 sec
Q.
Which safeguard within CIS Control 10 (Malware Defenses) specifically focuses on limiting the ability of an attacker to move laterally by blocking communication to known malicious domains?
29
30 sec
Q.
Which safeguard in CIS Control 10 (Malware Defenses) focuses on the management of removable media to prevent automatic execution of malicious code?
30
30 sec
Q.
According to CIS Control 12 (Network Infrastructure Management), which of the following actions is essential for maintaining the security of network devices such as routers and switches?
31
30 sec
Q.
Under CIS Control 12, what is the primary reason for maintaining an up-to-date network diagram that includes all physical and logical segmentation?
32
30 sec
Q.
Which specific activity is prescribed by CIS Control 12 to prevent the use of unauthorized or vulnerable communication paths within the network infrastructure?
33
30 sec
Q.
In the context of CIS Control 12, what is the significance of implementing a 'least privilege' approach to network architecture, specifically regarding network segmentation?
34
30 sec
Q.
Regarding CIS Control 12, what is the best practice for managing configuration files on network devices such as firewalls and routers?
35
30 sec
Q.
Which of the following practices is specifically required by CIS Control 12.10 (Management of Network Infrastructure) to prevent the bypass of security controls via physical or wireless means?
36
30 sec
Q.
Which specific measure under CIS Control 12 (Network Infrastructure Management) is designed to ensure that network devices are protected against vulnerabilities that could be exploited via the control plane?
37
30 sec
Q.
Under CIS Control 12 (Network Infrastructure Management), how should an organization handle the security of their 'Network Architecture' to mitigate the risk of lateral movement by an attacker?
38
30 sec
Q.
Under CIS Control 12, what is the recommended procedure for handling unused physical ports on network switches and routers located in common areas?
39
30 sec
Q.
Which requirement under CIS Control 12 (Network Infrastructure Management) is specifically aimed at ensuring the integrity and availability of network devices during a critical software vulnerability or hardware failure?
40
30 sec
Q.
An enterprise organization recently experienced a localized ransomware attack that encrypted several file servers. Following CIS Controls v8 (Control 11: Data Recovery), which action should the IT team prioritize to ensure they can restore operations while maintaining the integrity of the remaining network?
41
30 sec
Q.
A financial services firm is updating its Business Continuity Plan to align with CIS Control 11. They currently perform automated daily backups to a local NAS. To protect against a site-wide disaster or a coordinated ransomware attack that targets network-attached storage, which architectural requirement must be implemented?
42
30 sec
Q.
An organization is conducting its quarterly disaster recovery exercise. According to CIS Control 11.4, which metric should the security team prioritize to demonstrate that the data recovery process meets the specific business needs for a critical database system?
43
30 sec
Q.
An organization following CIS Control 11 (Data Recovery) wants to ensure their backup strategy is resilient against 'living-off-the-land' attacks where an intruder attempts to delete or modify backup files using compromised administrative credentials. Which technical control should they implement to meet this requirement?
44
30 sec
Q.
An organization is auditing its compliance with CIS Control 11.1, which focuses on the inventory of data. Why must the team perform a comprehensive data inventory before finalizing their data recovery strategy?
45
30 sec
Q.
An infrastructure manager is reviewing the organization's adherence to CIS Control 11.3, which concerns the protection of recovery data. The manager discovers that backups are encrypted, but the encryption keys are stored in a plain-text file on the same subnet as the backup server. Which action is most necessary to align with CIS best practices?
46
30 sec
Q.
An IT Auditor is reviewing an organization's Data Recovery procedures under CIS Control 11. They find that the organization performs daily backups but has never simulated a 'bare-metal' recovery of their critical domain controllers. According to CIS Control 11.4, what is the primary risk associated with this omission?
47
30 sec
Q.
A healthcare provider is refining its Data Recovery strategy under CIS Control 11. They have successfully implemented a daily automated backup of the Electronic Health Record (EHR) database. To comply with CIS Control 11.2 (Establish and Maintain Isolated Backups), how should they specifically handle their off-site copy to mitigate the risk of a 'timed' ransomware attack that remains dormant for weeks before encrypting data?
48
30 sec
Q.
An IT manager is tasked with implementing CIS Control 11.5: 'Ensure Backup Integrity.' To verify that the backups are actually viable for a full system restoration without manually checking every file, which technical process should the organization automate?
49
30 sec
Q.
An organization is updating its disaster recovery documentation to align with CIS Control 11. To satisfy the requirement for 'protecting' recovery data (Control 11.3), the security lead suggests transitioning from a single administrative account for the backup system to a Multi-Factor Authentication (MFA) approach using a separate, non-domain account. What is the primary security objective of this change?
50
30 sec
Q.
According to CIS Control 13 (Network Monitoring and Defense), why is it critical to maintain at least 30 days of captured network traffic header data, including NetFlow or IPFIX records?
51
30 sec
Q.
Which of the following activities is a core requirement of CIS Control 13.9, which focuses on the deployment of Host-Based Intrusion Detection Systems (HIDS) or Host-Based Intrusion Prevention Systems (HIPS)?
52
30 sec
Q.
Under CIS Control 13: Network Monitoring and Defense, what is the primary security objective of implementing a Centralized Log Management (CLM) system for network events?
53
30 sec
Q.
Which specific technique under CIS Control 13 (Network Monitoring and Defense) involves identifying and documenting the 'normal' traffic patterns of a network to better detect deviations that may indicate an attack?
54
30 sec
Q.
Which specific safeguard within CIS Control 13 (Network Monitoring and Defense) recommends the use of an Intrusion Detection System (IDS) or Intrusion Prevention System (IPS) at various layers of the network?
55
30 sec
Q.
Regarding CIS Control 13: Network Monitoring and Defense, what is the purpose of collecting and reviewing 'flow' data (such as NetFlow or IPFIX) even if the organization cannot perform full packet capture?
56
30 sec
Q.
Under CIS Control 13 (Network Monitoring and Defense), what is the specific purpose of implementing Safeguard 13.4, which focuses on the use of network-based filtering (such as DNS filtering or URL filtering)?
57
30 sec
Q.
In the context of CIS Control 13: Network Monitoring and Defense, what is the primary security benefit of deploying an application-layer filtering proxy or Web Application Firewall (WAF)?
58
30 sec
Q.
Which specific safeguard in CIS Control 13 (Network Monitoring and Defense) focuses on the use of threat intelligence to enhance the efficacy of an organization's network monitoring efforts?
59
30 sec
Q.
In the context of CIS Control 13: Network Monitoring and Defense, what is the primary purpose of 'Port Mirroring' (often referred to as SPAN) or using a physical Network TAP?