Did You Try Rebooting?
Ctrl Your Enthusiasm
Eat. Sleep. Hack. Repeat.
Son of a Breach!
Misc. - Let's Get SaaS-y
100

This is a document stipulating constraints and practices that a user must agree to for access to a corporate network or the Internet.

What is an Acceptable Use Policy?

100

Authenticating someone is a control for this leg of the CIA triad.

What is “Integrity”?

100

_________are generally younger hackers (high school or college age) with reasonably good computer skills and too much time on their hands.

What are Script Kiddies?

100

95% of cybersecurity breaches are caused by this.

What is Human Error?

100

An identification method that enables users to log in to multiple applications and websites with one set of credentials.

What is Single-Sign-On (SSO)?

200

This policy is often in place for employee use of personally-owned electronic assets that are used for work-related purposes.

What is a "Bring-Your-Own-Device" (BYOD) Policy?

200

This model outlines the obligations of CSPs and CSCs for securing cloud environments.

What is the Shared Responsibility Model?

200

This framework is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations.

What is the MITRE ATT&CK framework?

200

In 2020, a cybersecurity breach affected this prominent software company, leading to unauthorized access to its source code. 

What is SolarWinds?

BONUS QUESTION: This malware was used in the attack as a memory dropper.

200

This has all of the equipment installed but does not have active Internet or telecommunications facilities, and does not have current backups of data.

What is a Warm Site?

300

This is a modern security strategy based on the principle, "never trust, always verify."

What is Zero Trust?

300

This SOC 2 Type 2 examination opinion is issued when there are significant material and pervasive inaccuracies in the description and/or significant weaknesses in the design/operating effectiveness of controls.

What is an "adverse" opinion?

300

What is the term for the practice of gathering information about a target through social media and other public sources to launch targeted attacks?

What is "OSINT" or "Open Source Intelligence Gathering"?

300

This 2017 global ransomware attack that affected computers in over 150 countries was caused by this malware.

What is WannaCry?

300

This is an open-source system for automating deployment, scaling, and management of containerized applications.

What is Kubernetes?

400

Passed in March 2022, the Strengthening American Cybersecurity Act was passed by the Senate, which would require reporting by all nonfederal "critical infrastructure" construction to this government agency.

What is the Cybersecurity and Infrastructure Security Agency?

400

Information security policies, Organization of Information Security, Human Resources Security, Asset Management, Access Control, Cryptography, Physical and Environmental Security, Operations Security, Communications Security, Systems Acquisition and Maintenance, Supplier Relationships, Security Incident Management, Business Continuity Management, Compliance.

What are the 14 control domains of ISO 27001?

400

This type of penetration test is where the tester has an in-depth knowledge of the network and systems being tested, including network diagrams, IP addresses, and even the source code of custom applications.

What is a white box test?

400

This report is widely recognized across the cybersecurity industry for its comprehensive analysis of the global threat landscape, based on real-world data from actual security incidents and breaches.

What is the Verizon DBIR?

BONUS QUESTION: According to the 2023 Verizon DBIR, 1 out of every 5 breaches (19%) originates from this.

400

When TCP/IP was developed, the host table concept was expanded to a hierarchical name system for matching computer names and numbers known as this.

What is DNS?

BONUS QUESTION: This is the fastest IP address in the world.

500

This landmark OCC regulatory guidance was issued on June 6, 2023 and superseded bulletins 2013-29 and 2020-10.

What is OCC Bulletin 2023-17 OR What is Third-Party Relationships Interagency Guidance on Risk Management?

500

This type of report is performed by an independent CPA firm that expresses an opinion on the reliability and accuracy of an organization’s financial statements, system of internal controls, or other information.

What is an "attestation" report?

500

This type of testing is an automated software testing method that injects invalid, malformed, or unexpected inputs into a system to reveal software defects and vulnerabilities.

What is fuzz testing or fuzzing?

500

This is the global average cost of a data breach in 2023, according to the IBM Cost of a Data Breach Report. 

What is $4-5M? ($4.45M)

500

This is an authentication system developed by the Massachusetts Institute of Technology (MIT) and used to verify the identity of networked users.

What is kerberos?