Chapter 6 quizzes with answer

1. Question
A user is purchasing a new server for the company data center. The user wants disk striping with parity on three disks. Which RAID level should the user implement?

  • 5
  • 1+0
  • 0
  • 1

Explanation:
RAID 5 striping with parity would be the best choice.

2. Question
A user is asked to create a disaster recovery plan for a company. The user needs to have a few questions answered by management to proceed. Which three questions should the user ask management as part of the process of creating the plan? (Choose three.)

  • How long does the process take?
  • Where does the individual perform the process?
  • Can the individual perform the process?
  • Who is responsible for the process
  • What is the process?
  • Does the process require approval?

Explanation:
Disaster recovery plans are made based on the criticality of a service or process. Answers to questions of who, what, where, and why are necessary for a plan to be successful.

3. Question
A user was hired by a company to provide a highly available network infrastructure. The user wants to build redundancy into the network in case of a switch failure, but wants to prevent Layer 2 looping. What would the user implement in the network?

  • Spanning Tree Protocol
  • GLBP
  • VRRP
  • HSRP

Explanation:
Loops and duplicate frames cause poor performance in a switched network. The Spanning Tree Protocol (STP) provides a loop-free path through the switch network.

4. Question
A security breach has happened at a major corporation. The incident team has responded and executed their incident response plan. During which phase are lessons learned applied?

  • preparation
  • containment
  • recovery
  • analyze
  • post-incident
  • detection

Explanation:
One of the key aspects of an incident response plan is to look at how monitoring can be improved and management can help minimize the impact on business. This usually occurs after the incident has been handled.

5. Question
A team has been asked to create an incident response plan for security incidents. In what phase of an incident response plan does the team get management approval of the plan?

  • analysis
  • post-incident
  • detection
  • containment
  • preparation
  • recovery

Explanation:
When creating an incident plan for an organization, the team will require management buy-in of the plan during the initial planning phase.

6. Question
A user is asked to perform a risk analysis of a company. The user asks for the company asset database that contains a list of all equipment. The user uses this information as part of a risk analysis. Which type of risk analysis could be performed?

  1. qualitative
  2. hardware
  3. exposure factor
  4. quantitative

Explanation:
Physical items can be assigned a value for quantitative analysis.

7. Question
A user is evaluating the network infrastructure of a company. The user noted many redundant systems and devices in place, but no overall evaluation of the network. In a report, the user emphasized the methods and configurations needed as a whole to make the network fault tolerant. What is the type of design the user is stressing?

  • availability
  • comprehensive
  • resilient
  • spanning tree

Explanation:
In order to deploy a resilient design, it is critical to understand the needs of a business and then incorporate redundancy to address those needs.

8. Question
A user has completed a six month project to identify all data locations and catalog the location. The next step is to classify the data and produce some criteria on data sensitivity. Which two steps can the user take to classify the data? (Choose two.)

  • Determine permissions for the data.
  • Determine the user of the data.
  • Treat all the data the same.
  • Determine how often data is backed up.
  • Identify sensitivity of the data.
  • Establish the owner of the data.

Explanation:
Categorizing data is a process of determining first who owns the data then determining the sensitivity of the data.

9. Question
A user needs to add redundancy to the routers in a company. What are the three options the user can use? (Choose three.)

  • HSRP
  • VRRP
  • IPFIX
  • STP
  • RAID
  • GLBP

Explanation:
Three protocols that provide default gateway redundancy include VRRP, GLBP, and HSRP.

10. Question
A user is asked to evaluate the data center to improve availability for customers. The user notices that there is only one ISP connection, some of the equipment is out of warranty, there are no spare parts, and no one was monitoring the UPS which was tripped twice in one month. Which three deficiencies in high availability has the user identified? (Choose three.)

  • single points of failure
  • failure to detect errors as they occur
  • failure to design for reliability
  • failure to identify management issues
  • failure to prevent security incidents
  • failure to protect against poor maintenance

Explanation:
A data center needs to be designed from the outset for high availability with no single points of failure.

11. Question
A company is concerned with traffic that flows through the network. There is a concern that there may be malware that exists that is not being blocked or eradicated by antivirus. What technology can be put in place to detect potential malware traffic on the network?

  • IDS
  • firewall
  • IPS
  • NAC

Explanation:
A passive system (IDS) that can analyze traffic is needed to detect malware on the network and send alerts.

12. Question
A user is a consultant who is hired to prepare a report to Congress as to which industries should be required to maintain five nine availability. Which three industries should the user include in a report? (Choose three.)

  • retail
  • public safety
  • finance
  • food service
  • healthcare
  • education

Explanation:
Industries that are critical to everyday life like financial, healthcare, and public safety should have systems that are available 99.999% of the time (the five nines principle).

13. Question
A user is asked to evaluate the security posture of a company. The user looks at past attempts to break into the company and evaluates the threats and exposures to create a report. Which type of risk analysis could the user perform?

  • objective
  • subjective
  • qualitative
  • opinion

Explanation:
Two approaches to risk analysis are quantitative and qualitative. Qualitative analysis is based on opinions and scenarios.

14. Question
A user is running a routine audit of the server hardware in the company data center. Several servers are using single drives to host operating systems and multiple types of attached storage solutions for storing data. The user wants to offer a better solution to provide fault tolerance during a drive failure. Which solution is best?

  • tape backup
  • offsite backup
  • UPS
  • RAID

Explanation:
Fault tolerance is addressing a single point of failure, in this case the hard drives, have to be RAID.

15. Question
A user was hired as the new security officer. One of the first projects was to take inventory of the company assets and create a comprehensive database. Which three pieces of information would the user want to capture in an asset database? (Choose three.)

  • passwords
  • hardware network devices
  • users
  • workstations
  • groups
  • operating systems

Explanation:
Assets include all hardware devices and their operating systems.

16. Question
A user is redesigning a network for a small company and wants to ensure security at a reasonable price. The user deploys a new application-aware firewall with intrusion detection capabilities on the ISP connection. The user installs a second firewall to separate the company network from the public network. Additionally, the user installs an IPS on the internal network of the company. What approach is the user implementing?

  • risk based
  • attack based
  • layered
  • structured

Explanation:
Using different defenses at various points of the network creates a layered approach.

17. Question
The CEO of a company is concerned that if a data breach should occur and customer data is exposed, the company could be sued. The CEO makes the decision to buy insurance for the company. What type of risk mitigation is the CEO implementing?

  1. reduction
  2. mitigation
  3. avoidance
  4. transference

Explanation:
Buying insurance transfers the risk to a third party.