KING
QUEEN
SPADE
HEART
JOKER
100
Question: Which of the ACE engineers authored the security book - Protection Against Malicious Attacks
Answer: Roger Grimes
100
Question: Who is the Newest member of ACE Leadership Team
Answer: Suzanne Hall (Business Dev. Manager)
100
Question: Which Member of the ACE team used to be a celebrity
Answer: Shawn Tng
200
Question: Name the top 3 ISRM partners
Answer: - Network Security - Online Services - Identity & Access Management - Internal Audit & ERM - Global Security
200
Question: Name the Phases in SDL Track
Answer: Project Prerequisites, Requirements, Design, Implementation, Verification, Release, Sign Off.
200
Question: What is the largest ACE Vendor Integration engagement to date.
Answer: Skype
300
Question: What is the Data classification for an IP Address
Answer: MBI or PII
300
Question: Name one of the 4 Get Secure Goals
Answer: 1) Increase MSIT Application Security Scope 2) Move Application Security Upstream 3) Evolve ISRM-ACE Analyst engagement from code reviews to Trusted Security Advisor with MSIT Engineering 4) Reduce Risk to the overall Microsoft Application Portfolio
300
Question: What is the name of the ACE process that ensures our engagements are consistent and aligns to our ACE principles
Answer: Bid Review Process
400
Question: What are the ACE FY12 Top Programs
Answer: Get Secure, Azure, Windows Phone, Infrastructure Protection Program (IPP), Threat Scenario Analysis (TSAP), Service Management/Archer Integration
400
Question: Name two popular SDL tool for Security Analyst
Answer: SDL Threat Modeling Tool - CAT.NET - WACA - Binscope
400
Question: What are the major Programs within Operations team
Answer: Data Loss Prevention (DLP), Identity and Access Management (IAM), and Security Information and Event Management (SIEM)
400
Question: What complimentary App.Sec. Service Offering would a Biz. Dev. recommend alongside a Code Review?
Answer: Threat Modeling – Design Review
400
Question: What are the 3 main authentication Factors
Answer: Something you know - Something you have - and something you are.
500
Question: What are ACE principles
Answer: - Collaboration, - Delight our customers, - Individual and shared Accountability, - Operational Precision - Innovation & Impact - Risk Management is our Passion!
500
Question: Name 5 ACE Application Security Offerings (9)
Answer: - Penetration Testing - Privacy Assessment - ASAA, App.Sec Assessment (Code Review) - App.Sec Training (Workshop) - Azure App.Sec Assessment - Get Secure (MSIT Eng.) - Mobile AppSec. Assessment
500
Question: Name 3 Security Domains we assess in our VMA offering based on ISO 27K Framework
Answer: • Security Policy • Organizing Information Security • Asset Management • Human Resources Security • Physical and Environmental Security • Communications and Operations Management • Access Control • Information Systems Acquisition, Development and Maintenance • Information Security Incident Management • Business Continuity Management • Compliance
500
Question: List the Top 3 countries hosting Malicious URL’s
Answer: #1 – China #2 - U.S.A #3 - Korea
500
Question: What is the most prevalent type of attack on Microsoft Customer Service Support Centers
Answer: Social Engineering
M
e
n
u