Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

CDS 348 Final Exam Study Questions and Answers

Rating
-
Sold
-
Pages
18
Grade
A+
Uploaded on
15-10-2024
Written in
2024/2025

CDS 348 Final Exam Study Questions and Answers A CSIRT model in which a single CSIRT handles incidents throughout the organization is called a(n) - Ans:-central CSIRT A CSIRT model that is effective for large organizations and for organizations with major computing resources at distant locations is the - Ans:-distributed CSIRT A key step in the ____ approach to incident response is to discover the identity of the intruder while documenting his or her activity. - Ans:-apprehend and prosecute Giving the IR team the responsibility for ____ is generally not recommended. - Ans:-patch management In the absence of the assigned team manager, the ____ should assume authority for overseeing and evaluating a provided service. - Ans:-deputy team manager One way to build and maintain staff skills is to develop incident-handling ____ and have the team members discuss how they would handle them. - Ans:-scenarios The announcement of an operational CSIRT should minimally include - Ans:-contact methods and numbers GRACEAMELIA 2024/2025 ACADEMIC YEAR ©2024. ALL RIGHTS RESERVED. FIRST PUBLISH OCTOBER, 2024 Page 2/18 The champion for the CSIRT may be the same person as the champion for the entire IR function- typically, the - Ans:-chief information officer The CSIRT must have a clear and concise ____ statement that, in a few sentences, unambiguously articulates what it will do - Ans:-mission The determination of what systems fall under the CSIRT 's responsibility is called its ____. - Ans:-scope of operations The first step in building a CSIRT is to - Ans:-obtain management support and buy-in The focus during a(n) ____ is on learning what worked, what didn't, and where communications and response procedures may have failed. - Ans:-after action review The organization must first understand what skills are needed to effectively respond to an incident. If necessary, management must determine if it is willing to acquire needed ____ to fill in the gaps. - Ans:-personnel Those services performed in response to a request or a defined event such as a help desk alert are called - Ans:-reactive services Those services undertaken to prepare the organization or the CSIRT constituents to protect and secure systems in anticipation of problems, attacks, or other events are called - Ans:- proactive services GRACEAMELIA 2024/2025 ACADEMIC YEAR ©2024. ALL RIGHTS RESERVED. FIRST PUBLISH OCTOBER, 2024 Page 3/18 When an organization completely outsources its IR work, typically to an on-site contractor, it is called a(n) ____ model. - Ans:-fully outsourced As soon as the CSIRT is able to determine what exactly is happening, it is expected to report its preliminary finding to management. - Ans:-True One of the first signals that an organization is making progress in the development of its IR program, specifically in the development of its CSIRT, is a dramatic drop in the number of identified incidents. - Ans:-False Regardless of which IR model an organization chooses, multiple employees should be in charge of incident response. - Ans:-False The CSIRT is also known as the IR Reaction Team. - Ans:-True A ____ attack is much more substantial than a DoS attack because of the use of multiple systems to simultaneously attack a single target - Ans:-distributed denial-of-service A ____ is a small quantity of data kept by a Web site as a means of recording that a system has visited that Web site. - Ans:-cookie Which of the following is an example of a UA (Unauthorized Access) attack? - Ans:- Modifying Web-based content without permission GRACEAMELIA 2024/2025 ACADEMIC YEAR ©2024. ALL RIGHTS RESERVED. FIRST PUBLISH OCTOBER, 2024 Page 4/18 Known as ____, procedures for regaining control of systems and restoring operations to normalcy are the heart of the IR plan and the CSIRT's operations. - Ans:-IR reaction strategies Many malware attacks are ____ attacks, which involve more than one type of malware and/or more than one type of transmission method. - Ans:-blended The CSIRT may not wish to "tip off" attackers that they have been detected, especially if the organization is following a(n) ____ approach - Ans:-apprehend and prosecute The number-one IU preparation-and-prevention strategy is - Ans:-organizational policy There are a number of professional IR agencies, such as ____, that can provide additional resources to help prevent and detect DoS incidents - Ans:-US-CERT When a second attack, using the means and methods of the first attack is undertaken while the first attack is still underway, this is considered a(n) ____ recurrence. - Ans:-concurrent When an alert warns of new malicious code that targets software used by an organization, the first response should be to research the new virus to determine whether it is ____. - Ans:- real When an incident includes a breach of physical security, all aspects of physical security should be escalated under a containment strategy known as ____. - Ans:-lockdown

Show more Read less
Institution
2024/2025
Course
2024/2025

Content preview

GRACEAMELIA 2024/2025 ACADEMIC YEAR ©2024. ALL RIGHTS
RESERVED. FIRST PUBLISH OCTOBER, 2024



CDS 348 Final Exam Study Questions
and Answers

A CSIRT model in which a single CSIRT handles incidents throughout the organization is called

a(n) - Ans:✔✔-central CSIRT


A CSIRT model that is effective for large organizations and for organizations with major

computing resources at distant locations is the - Ans:✔✔-distributed CSIRT


A key step in the ____ approach to incident response is to discover the identity of the intruder

while documenting his or her activity. - Ans:✔✔-apprehend and prosecute


Giving the IR team the responsibility for ____ is generally not recommended. - Ans:✔✔-patch

management


In the absence of the assigned team manager, the ____ should assume authority for overseeing

and evaluating a provided service. - Ans:✔✔-deputy team manager


One way to build and maintain staff skills is to develop incident-handling ____ and have the

team members discuss how they would handle them. - Ans:✔✔-scenarios


The announcement of an operational CSIRT should minimally include - Ans:✔✔-contact

methods and numbers

Page 1/18

,GRACEAMELIA 2024/2025 ACADEMIC YEAR ©2024. ALL RIGHTS
RESERVED. FIRST PUBLISH OCTOBER, 2024

The champion for the CSIRT may be the same person as the champion for the entire IR function-

typically, the - Ans:✔✔-chief information officer


The CSIRT must have a clear and concise ____ statement that, in a few sentences,

unambiguously articulates what it will do - Ans:✔✔-mission


The determination of what systems fall under the CSIRT 's responsibility is called its ____. -

Ans:✔✔-scope of operations


The first step in building a CSIRT is to - Ans:✔✔-obtain management support and buy-in


The focus during a(n) ____ is on learning what worked, what didn't, and where communications

and response procedures may have failed. - Ans:✔✔-after action review


The organization must first understand what skills are needed to effectively respond to an

incident. If necessary, management must determine if it is willing to acquire needed ____ to fill

in the gaps. - Ans:✔✔-personnel


Those services performed in response to a request or a defined event such as a help desk alert

are called - Ans:✔✔-reactive services


Those services undertaken to prepare the organization or the CSIRT constituents to protect and

secure systems in anticipation of problems, attacks, or other events are called - Ans:✔✔-

proactive services




Page 2/18

, GRACEAMELIA 2024/2025 ACADEMIC YEAR ©2024. ALL RIGHTS
RESERVED. FIRST PUBLISH OCTOBER, 2024

When an organization completely outsources its IR work, typically to an on-site contractor, it is

called a(n) ____ model. - Ans:✔✔-fully outsourced


As soon as the CSIRT is able to determine what exactly is happening, it is expected to report its

preliminary finding to management. - Ans:✔✔-True


One of the first signals that an organization is making progress in the development of its IR

program, specifically in the development of its CSIRT, is a dramatic drop in the number of

identified incidents. - Ans:✔✔-False


Regardless of which IR model an organization chooses, multiple employees should be in charge

of incident response. - Ans:✔✔-False


The CSIRT is also known as the IR Reaction Team. - Ans:✔✔-True


A ____ attack is much more substantial than a DoS attack because of the use of multiple

systems to simultaneously attack a single target - Ans:✔✔-distributed denial-of-service


A ____ is a small quantity of data kept by a Web site as a means of recording that a system has

visited that Web site. - Ans:✔✔-cookie


Which of the following is an example of a UA (Unauthorized Access) attack? - Ans:✔✔-

Modifying Web-based content without permission




Page 3/18

Written for

Institution
2024/2025
Course
2024/2025

Document information

Uploaded on
October 15, 2024
Number of pages
18
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$12.99
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
GraceAmelia West Virginia University
Follow You need to be logged in order to follow users or courses
Sold
99
Member since
2 year
Number of followers
32
Documents
8971
Last sold
1 month ago
GraceAmelia\'s Emporium

Get a well Researched and Accurate Study Materials to Boost Your Grades and Excel Academically Offered by Seller Grace.

2.8

8 reviews

5
2
4
1
3
1
2
1
1
3

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions