Saved assistant message 2026-06-24 00:30

Untuk Section A (MCQ), soalan biasanya akan guna perkataan "pancing" atau Keywords. Kalau Aliah nampak keyword ni, jawapannya mesti yang itu.

Ini adalah Keyword Cheat Sheet untuk MCQ:


TOPIC 1: Security Process (PICERL)

If you see this Keyword...

The Answer is...

"Detect", "Confirm", "Notice"

Identification

"Stop spread", "Isolate", "Disconnect"

Containment

"Remove virus", "Delete malware", "Patch hole"

Eradication

"Restore", "Backup", "Normal operation"

Recovery

"Improve", "Future prevention", "Final report"

Lessons Learned

TOPIC 2: Frameworks & Standards

If you see this Keyword...

The Answer is...

"Guidance", "Blueprint", "High-level"

Framework (NIST/COBIT)

"Mandatory", "Recipe", "Specific rules"

Standard (ISO/PCI-DSS)

"Law", "Government", "Fines", "Personal data"

Regulation (PDPA/GDPR)

"Service Management", "Helpdesk"

ITIL

TOPIC 3: ISO 27001 (ISMS)

If you see this Keyword...

The Answer is...

"Continuous improvement"

PDCA Cycle

"Checklist of controls", "Selected controls"

SoA (Statement of Applicability)

"114 controls", "Domains"

Annex A

"Management system for data"

ISMS

TOPIC 4: VAPT (The Boxes & Phases)

If you see this Keyword...

The Answer is...

"Find weaknesses", "Passive scan", "List"

Vulnerability Assessment (VA)

"Active attack", "Exploit", "Prove risk"

Penetration Testing (PT)

"Zero knowledge", "External hacker"

Black Box

"Full knowledge", "Source code", "Admin"

White Box

"Permission", "Agreement", "Legal"

Pre-engagement

TOPIC 5: Risk Assessment (AMTA)

If you see this Keyword...

The Answer is...

"Reduce risk", "Install firewall/antivirus"

Mitigation

"Share risk", "Insurance", "Outsource"

Transfer

"Do nothing", "Low impact", "Acceptable"

Acceptance

"Stop activity", "Eliminate threat"

Avoidance

"Leftover risk", "Remaining risk"

Residual Risk

TOPIC 6: Lab Activities (Tools & Attacks)

If you see this Keyword...

The Answer is...

"Port scanning", "Find open ports"

Nmap

"Bypass login", "' OR 1=1 --", "Database"

SQL Injection

"Steal cookies", "

XSS (Cross-Site Scripting)

"Exploitation framework", "Hack tool"

Metasploit

"Brute force password", "Guessing"

Hydra


💡 Contoh Soalan MCQ (Try test):

Q1: Which phase of incident response involves isolating the infected system to stop the spread? A) Identification B) Containment (Keyword: Stop spread) C) Recovery D) Eradication

Q2: What is the document that lists all selected controls for ISO 27001? A) Annex A B) PDCA C) SoA (Keyword: Lists selected controls) D) ISMS

Q3: An attacker tries to bypass a login page by typing ' OR 1=1 --. What attack is this? A) XSS B) Brute Force C) SQL Injection (Keyword: ' OR 1=1) D) Port Scan


Tips Aliah: Dalam MCQ, jangan baca soalan panjang-panjang. Cari Keyword yang saya bold kan tu, terus pilih jawapan.

Nak saya bagi lagi soalan "pancing" macam ni ke?