Security Blue Team Level 1 Exam ||Verified Exam!!||
Most Recent Exam Actual Complete Real Exam
Questions And Correct Answers (Verified Answers)
Already Graded A+ || Newest Exam!!!
(Host-based Intrusion Detection System) Reacts to
unusual or malicious system activity and generates alerts -
Answer-HIDS
Can use infrared to detect the presence of a human
passing in front of a sensor - Answer-Motion Detector
Endpoint Detection and Response - This security solution
comes in the form of a dashboard that analysts can log
into and analyse alerts generated by software agents that
are installed on endpoints, and can detect and prevent
malicious activity. - Answer-EDR
Administrative (Policies)
Physical (CCTV/locked doors)
Technical (Firewalls) - Answer-3 Categories of Security
Controls
,2|Page
A Media Access Control (MAC) address is a hardware
identification number that uniquely identifies each device
on a network. - Answer-MAC
provides an identity to a networked device on the internet.
- Answer-Internet Protocol (IP) address
an internet layer protocol used by network devices to
diagnose network communication issues. - Answer-
Internet Control Message Protocol (ICMP)
A technical control that can restrict the traffic coming in
and going out of it and generates logs about network
activity - Answer-Firewall
Uses Blacklists and reputation checks to stop unwanted
emails being delivered to employees mailboxes - Answer-
Spam Filter
(Network-based Intrusion Detection System)Takes
Automated actions to react to unusual or malicious
network activity - Answer-NIPS
,3|Page
a protocol that allows datagrams to be sent without
connection in IP-based networks. - Answer-User
Datagram Protocol (UDP)
3 Types of Physical Security - Answer-1. Access Controls
(RFID badge, turnstile)
2. Monitoring Controls (CCTV)
3. Deterrents (electric fence)
NIDS? wdid? - Answer-(network intrusion detection
system)
Monitors network to generate alerts for human analyst to
investigate
3 Types of NIDS - Answer-1. Inline (in path of network
traffic, can be NIPS)
2. Network Tap (Tapping into physical connection)
3. Passive (Span port / port mirroring)
NIPS? wdid? - Answer-(network intrusion prevention
system)
, 4|Page
Monitors network traffic to detect and take preventive
action against suspicious activities
Firewalls? - Answer-Creates separated zones in network
by restricting certain types of traffics
3 Types of Firewalls? - Answer-Standard firewall: Run on
dedicated hardware at keypoints of network;
Local firewall: Running on endpoints
Web application firewalls: On internet facing web servers /
web apops
Event Monitoring? - Answer-Monitoring of activity logs
from network devices
Web proxy logs? - Answer-Logs that show internet activity
of users
Perimeter firewall? - Answer-Firewall at the outer most
edge of an organisation. All external traffic will travel
through here (can be watched for port scanning)