SAC Assessment & Evaluation Methods 2 — Questions and Answers
Question 1: Which metric best measures the effectiveness of a patch management program over time?
- Number of patches applied per month
- Mean time to patch (MTTP) critical vulnerabilities (Correct answer)
- Total size of patches deployed
- Number of servers in the environment
Correct answer: Mean time to patch (MTTP) critical vulnerabilities
Mean time to patch measures how quickly the organization remediates known vulnerabilities, directly reflecting patch management effectiveness.
Question 2: During a system audit, you discover that log retention is set to 30 days but policy requires 90 days. What type of finding is this?
- Vulnerability
- Compliance gap (Correct answer)
- Configuration drift
- Security incident
Correct answer: Compliance gap
A compliance gap exists when an operational setting does not meet the documented policy or regulatory requirement.
Question 3: Which evaluation approach compares system performance against a previously recorded baseline?
- Trend analysis
- Benchmarking
- Baseline comparison (Correct answer)
- Capacity planning
Correct answer: Baseline comparison
Baseline comparison evaluates current metrics against a known-good snapshot to detect degradation or anomalies.
Question 4: A sysadmin wants to assess whether CPU utilization spikes are recurring at a specific time. Which tool category is most appropriate?
- Inventory scanner
- Performance monitoring with historical graphing (Correct answer)
- Network packet analyzer
- Configuration management database
Correct answer: Performance monitoring with historical graphing
Performance monitoring tools with historical graphing (e.g., Grafana, Nagios) reveal time-correlated patterns in resource utilization.
Question 5: What is the primary purpose of a post-incident review (PIR)?
- Assign blame to responsible staff
- Identify root causes and prevent recurrence (Correct answer)
- Generate invoices for downtime costs
- Reset all affected systems to defaults
Correct answer: Identify root causes and prevent recurrence
A PIR (also called a post-mortem) focuses on root cause analysis and process improvements to prevent similar incidents.
Question 6: Which of the following best describes a gray-box assessment?
- Assessor has no prior knowledge of the environment
- Assessor has full administrative access and documentation
- Assessor has partial knowledge such as network diagrams but no credentials (Correct answer)
- Assessor only reviews physical security controls
Correct answer: Assessor has partial knowledge such as network diagrams but no credentials
Gray-box testing provides the assessor with limited information (e.g., architecture diagrams) to simulate a partially informed attacker or reviewer.
Question 7: In capacity planning assessments, what does the 80% rule refer to?
- 80% of users must pass security training annually
- Resource utilization should not exceed 80% to allow headroom for spikes (Correct answer)
- 80% of patches must be applied within SLA
- Systems should be replaced after 80% of their expected lifespan
Correct answer: Resource utilization should not exceed 80% to allow headroom for spikes
The 80% rule states that sustained resource utilization above 80% indicates insufficient headroom, signaling the need for capacity expansion.
Which metric best measures the effectiveness of a patch management program over time?