Employees are installing unauthorized software on work computers to play games during breaks. What policy should management enforce to prevent this?
A server administrator wants to ensure only trained personnel can configure server settings. Which policy addresses this need?
A new hire is required to create a password for their company account. The organization wants to prevent the use of simple words like “password” or “12345.” Which setting enforces this?
A user attempts to log in three times with the wrong password. The system locks their account for 15 minutes. Which policy setting does this reflect?
Employees frequently reuse passwords across accounts, creating a security risk. Which policy setting mitigates this issue?
A company wants to prevent employees from accessing social media during work hours. Which policy enforces this?
An employee requests specialized software needed for their role, but the organization wants to control installations. Which policy governs this request?
A company requires all servers to disable unused services and protocols. Which policy is this an example of?
A company enforces that passwords must include uppercase letters, lowercase letters, numbers, and symbols. Why is this required?
A device is connected to a public Wi-Fi network. To prevent attacks targeting open ports, which security control should be active?
A company requires users to change passwords every 90 days but recently learned frequent changes can lead to predictable patterns. What does NIST recommend?
An IT administrator notices that an employee has a very old version of their operating system. What risk does this pose?
A system prompts users to enter passwords with at least one uppercase letter, one number, and one special character. Which login setting is being enforced?
A host-based firewall uses rules that check the first match and then stop. Which behavior does this describe?
An organization wants to prevent employees from installing outdated or unapproved software. What policy addresses this?
An employee writes passwords on sticky notes because they are hard to remember. Which control could reduce this behavior?
A device periodically scans files against a database of known malware signatures. What is this an example of?
Which of the following is an example of a managerial control rather than a technical control?
An employee’s account is locked after 5 failed login attempts. This prevents:
A device has outdated antivirus definitions, and malware goes undetected. What concept does this illustrate?
You are a cybersecurity analyst tasked with assessing the security of a company device. The company has provided the following information for the device: an Acceptable Use Policy (AUP), a Password Policy, a Software Installation Policy, a Host-Based Firewall ACL, and the current operating system version.
Your task is to evaluate the security of the device and provide clear, justified recommendations. Answer each of the questions below using evidence from the scenario:
Acceptable Use Policy: Assess whether the AUP adequately protects the device. Are there any potential issues or risks based on the rules provided? Explain your reasoning.
Password Policy: Evaluate whether the password policy provides sufficient protection for user accounts. Are the password requirements strong enough? Identify any weaknesses and justify your answer.
Software Installation Policy: Determine whether the software installation policy appropriately controls what users can install. Are there any gaps or unnecessary restrictions? Explain your reasoning.
Host-Based Firewall ACL: Review the firewall rules and assess whether they allow the necessary traffic while blocking risky or unnecessary traffic. Be specific about what types of traffic should be allowed or blocked and provide justification.
Operating System Version: Compare the current OS version to the latest available version. Does the device need to be updated or patched? Explain why or why not, using evidence from the scenario.
Provide clear, concise answers for each section. Each part is worth 1 point, for a total of 5 points.
You are reviewing a company laptop assigned to a marketing employee. The following policies and settings are currently in place:
Acceptable Use Policy (AUP) Excerpt:
Employees may access company-approved websites related to their role.
Social media and gaming websites are allowed during breaks.
Employees must keep all software updated to the latest version.
USB drives and external storage devices are allowed.
Password Policy:
Passwords must be at least 8 characters long.
Passwords must include at least one uppercase letter and one number.
Users may reuse previous passwords after 30 days.
Passwords must be changed every 180 days.
Software Installation Policy:
Employees may install any software they need for their role without IT approval.
Specialized software requests for other roles must be submitted to IT.
No list of approved software is maintained.
Host-Based Firewall ACL (Rules applied top-to-bottom):
Allow all outbound traffic on ports 80 (HTTP) and 443 (HTTPS).
Deny inbound traffic on all ports except 22 (SSH) and 3389 (RDP).
Deny all other outbound traffic.
Operating System Version:
Current OS: Windows 10, version 21H2
Latest OS version: Windows 10, version 22H2
Acceptable Use Policy: Assess whether the AUP adequately protects the device. Are there any potential issues or risks based on the rules provided? Explain your reasoning.
Acceptable Use Policy (AUP) Excerpt:
Employees may access company-approved websites related to their role.
Social media and gaming websites are allowed during breaks.
Employees must keep all software updated to the latest version.
USB drives and external storage devices are allowed.
Password Policy: Evaluate whether the password policy provides sufficient protection for user accounts. Are the password requirements strong enough? Identify any weaknesses and justify your answer.
Password Policy:
Passwords must be at least 8 characters long.
Passwords must include at least one uppercase letter and one number.
Users may reuse previous passwords after 30 days.
Passwords must be changed every 180 days.
Software Installation Policy: Determine whether the software installation policy appropriately controls what users can install. Are there any gaps or unnecessary restrictions? Explain your reasoning.
Software Installation Policy:
Employees may install any software they need for their role without IT approval.
Specialized software requests for other roles must be submitted to IT.
No list of approved software is maintained.
Host-Based Firewall ACL: Review the firewall rules and assess whether they allow the necessary traffic while blocking risky or unnecessary traffic. Be specific about what types of traffic should be allowed or blocked and provide justification.
Host-Based Firewall ACL (Rules applied top-to-bottom):
Allow all outbound traffic on ports 80 (HTTP) and 443 (HTTPS).
Deny inbound traffic on all ports except 22 (SSH) and 3389 (RDP).
Deny all other outbound traffic.
Operating System Version: Compare the current OS version to the latest available version. Does the device need to be updated or patched? Explain why or why not, using evidence from the scenario.
Operating System Version:
Current OS: Windows 10, version 21H2
Latest OS version: Windows 10, version 22H2