Tag the questions with any skills you have. Your dashboard will track each student's mastery of each skill.
Give this quiz to my class
Q 1/20
Score 0
Ebba has received a new initiative for her security team to perform an in-house penetration test. What is the first step that Ebba should undertake?
30
Documentation
Budgeting
Approval
Planning
Q 2/20
Score 0
Which of the following is NOT a characteristic of a penetration test?
30
Automated
Performed occasionally
Finds deep vulnerabilities
May use internal employees or external consultants
20 questions
Q.
Ebba has received a new initiative for her security team to perform an in-house penetration test. What is the first step that Ebba should undertake?
1
30 sec
Q.
Which of the following is NOT a characteristic of a penetration test?
2
30 sec
Q.
Linnea has requested to be placed on the penetration testing team that scans for vulnerabilities to exploit them. Which team does she want to be placed on?
3
30 sec
Q.
Lykke's supervisor is evaluating whether to use internal security employees to conduct a penetration test. Lykke does not consider this a good idea and has created a memo with several reasons they should not be used. Which of the following would NOT be part of that memo?
4
30 sec
Q.
What penetration testing level name is given to testers who have no knowledge of the network and no special privileges?
5
30 sec
Q.
Which of the following is NOT an advantage of crowdsourced penetration testing?
6
30 sec
Q.
Tilde is working on a contract with the external penetration testing consultants. She does not want any executives to receive spear-phishing emails. Which rule of engagement would cover this limitation?
7
30 sec
Q.
Which is the final rule of engagement that would be conducted in a pen test?
8
30 sec
Q.
What is another name for footprinting?
9
30 sec
Q.
When researching how an attack recently took place, Nova discovered that the threat actor, after penetrating the system, started looking to move through the network with their elevated position. What is the name of this technique?
10
30 sec
Q.
What are documents that are authored by technology bodies employing specialists, engineers, and scientists who are experts in those areas?
11
30 sec
Q.
Which of the following is NOT a general information source that can provide valuable in-depth information on cybersecurity?
12
30 sec
Q.
Which of the following is a standard for the handling of customer card information?
13
30 sec
Q.
Which of the following are developed by established professional organizations or government agencies using the expertise of seasoned security professionals?
14
30 sec
Q.
Which group is responsible for the Cloud Controls Matrix?
15
30 sec
Q.
Tuva’s supervisor wants to share a recent audit outside the organization. Tuva warns him that this type of audit can only be read by those within the organization. What audit does Tuva’s supervisor want to distribute?
16
30 sec
Q.
Which ISO contains controls for managing and controlling risk?
17
30 sec
Q.
Which premise is the foundation of threat hunting?
18
30 sec
Q.
Which of the following can automate an incident response?
19
30 sec
Q.
Which of the following is not something that a SIEM can perform?