A vulnerability scan of a web server that is exposed to the internet was recently completed. A security analyst is reviewing the resulting vector strings:Vulnerability 1: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L, Vulnerability 2: CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H, Vulnerability 3: CVSS:3.0/AV:A/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:L, Vulnerability 4: CVSS:3.0/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:L.Which of the following vulnerabilities should be patched first?
Rationale
Vulnerability 1 exhibits a CVSS score indicating high confidentiality impact, low integrity impact, and low availability impact. This combination suggests a potential threat to sensitive data confidentiality without immediate risks to data integrity or system availability.
A) Vulnerability 1 Vulnerability 1's CVSS score highlights a critical confidentiality impact due to potential unauthorized access to sensitive information. While integrity and availability may face lower risks, the importance of preserving data confidentiality, especially in web server environments, necessitates prompt remediation of this vulnerability.
B) Vulnerability 2 Vulnerability 2 presents a CVSS score with a moderate confidentiality impact, low integrity impact, and high availability impact. Although it poses risks to data confidentiality, the lower severity compared to Vulnerability 1 prioritizes addressing the latter first to mitigate higher confidentiality threats.
C) Vulnerability 3 Vulnerability 3's CVSS score indicates a low confidentiality impact, high integrity impact, and low availability impact. While data integrity is at risk, the lower impact on confidentiality compared to Vulnerability 1 implies that addressing Vulnerability 1 takes precedence to safeguard critical data confidentiality.
D) Vulnerability 4 Vulnerability 4's CVSS score reveals high confidentiality impact, no integrity impact, and low availability impact. Despite sharing a high confidentiality impact with Vulnerability 1, the absence of integrity risks in Vulnerability 4 positions Vulnerability 1 as the primary concern for immediate patching to address data confidentiality vulnerabilities effectively.
Conclusion Prioritizing vulnerability patching is crucial for maintaining web server security. In this scenario, remediation should start with Vulnerability 1 due to its significant confidentiality impact, aligning with cybersecurity best practices to address critical vulnerabilities efficiently and reduce potential data breaches.
A SOC analyst identifies the following content while examining the output of a debugger command over a client-server application: getConnection(database01,'alpha','AxTv.127GdCx94GTd'); Which of the following is the most likely vulnerability in this system?
Rationale
The presence of explicit credentials like 'alpha' and 'AxTv.127GdCx94GTd' within the debugger output indicates a hard-coding of sensitive information directly into the application's source code or configuration files. This practice poses a significant security risk, as anyone with access to the code can easily extract these credentials and potentially compromise the system.
A) Lack of input validation While input validation is a crucial security measure to prevent unexpected user inputs from causing issues, the presence of hard-coded credentials in this context suggests a different type of vulnerability related to the storage and handling of sensitive information rather than user input validation.
B) SQL injection SQL injection involves manipulating input data to execute unauthorized SQL commands, typically targeting databases. In this scenario, the presence of hard-coded credentials does not directly indicate susceptibility to SQL injection attacks, as the issue lies in the exposure of credentials rather than in the structure of SQL queries.
C) Hard-coded credential The inclusion of specific credentials within the debugger output strongly suggests that the application is using hard-coded credentials, which is a security vulnerability due to the exposure of sensitive information. This practice undermines security best practices and can lead to unauthorized access if these credentials are compromised.
D) Buffer overflow Buffer overflow vulnerabilities occur when a program writes more data to a buffer than it can hold, potentially leading to erratic behavior or exploitation by attackers. The presence of hard-coded credentials in the debugger output is not indicative of a buffer overflow vulnerability, as this issue pertains to memory management and not the exposure of credentials.
Conclusion The most likely vulnerability in the system based on the information provided is the presence of hard-coded credentials. This security flaw poses a significant risk to the confidentiality and integrity of the system's data, highlighting the importance of securely managing credentials and implementing more robust authentication mechanisms.
A malicious actor has gained access to an internal network by means of social engineering. The actor does not want to lose access in order to continue the attack. Which of the following best describes the current stage of the Cyber Kill Chain that the threat actor is currently operating in?
Rationale
At this stage of the Cyber Kill Chain, the threat actor has successfully leveraged the initial access gained through social engineering to exploit vulnerabilities within the internal network. Exploitation involves taking advantage of these weaknesses to achieve the attacker's goals, such as gaining further access or deploying malicious payloads.
A) Weaponization Weaponization occurs when the attacker creates or modifies a tool or payload to use in the attack. This stage involves turning an exploit into a weapon that can be used to compromise the target system. Since the threat actor has already gained access in this scenario, weaponization has likely already occurred prior to the current stage.
B) Reconnaissance Reconnaissance involves gathering information about the target to identify potential vulnerabilities and plan the attack. While reconnaissance is an essential early stage of the Cyber Kill Chain, the threat actor in this scenario has already progressed beyond this point by gaining access to the internal network.
C) Delivery Delivery is the stage where the attacker delivers the malicious payload to the target system, often through methods like phishing emails or compromised websites. In this case, the threat actor has already breached the network through social engineering and is focused on maintaining access rather than delivering a new payload.
D) Exploitation Exploitation is the correct stage for the current scenario, as the threat actor is actively exploiting vulnerabilities within the internal network to further their attack objectives. By exploiting these weaknesses, the attacker can escalate their access and potentially move laterally within the network to expand their control.
Conclusion In this scenario, the threat actor has progressed to the exploitation stage of the Cyber Kill Chain after gaining initial access through social engineering. By exploiting vulnerabilities within the internal network, the attacker aims to prolong their access and advance their malicious activities, highlighting the critical importance of vulnerability management and detection in cybersecurity defense strategies.
A new SOC manager reviewed findings regarding the strengths and weaknesses of the last tabletop exercise in order to make improvements. Which of the following should the SOC manager utilize to improve the process?
Rationale
The lessons-learned register is a crucial tool for gathering insights and feedback from past exercises or incidents to enhance future processes. It captures valuable information on what worked well and what areas require improvement, guiding the SOC manager in refining strategies effectively.
A) The most recent audit report While audit reports provide valuable information on compliance and security posture, they may not offer specific insights tailored to the tabletop exercise process. The focus of an audit report typically differs from the detailed feedback and recommendations found in a lessons-learned register.
B) The incident response playbook The incident response playbook outlines predefined steps and procedures to respond to specific security incidents. While important for incident handling, its utility in improving tabletop exercises is limited compared to a lessons-learned register, which captures broader insights and feedback.
C) The incident response plan The incident response plan details the overall strategy and structure for responding to security incidents. While essential for guiding incident response efforts, it may not provide the detailed feedback and specific improvement areas that a lessons-learned register offers for tabletop exercise enhancements.
D) The lessons-learned register The lessons-learned register is a dedicated repository for recording observations, feedback, and recommendations following exercises or incidents. It serves as a valuable resource for identifying strengths, weaknesses, and areas for improvement, making it a key tool for enhancing the effectiveness of future tabletop exercises.
Conclusion In the context of improving tabletop exercises, the lessons-learned register stands out as the most suitable resource for the SOC manager. By leveraging insights and feedback from past exercises stored in the register, the manager can implement targeted enhancements and adjustments to optimize the tabletop exercise process for better preparedness and response capabilities.
The security team reviews a web server for XSS and runs the following Nmap scan# nmap -p80 --script http-unsafe-output-escaping 172.31.15.2 PORT STATE SERVICE REASON 80/tcp open http syn-ack | http-unsafe-output-escaping: | Characters ["] ['] reflected in parameter id at | http://172.31.15.2/1.php?id=2 |_ Characters [>] ["] ['] reflected.Which of the following most accurately describes the result of the scan?
Rationale
The Nmap scan results indicate that the web server's parameter ID is vulnerable to unsafe output escaping, allowing special characters to be reflected without proper filtering or encoding.
A) An output of characters > and ' as the parameters used in the attempt This choice is incorrect because the scan does not specifically mention the characters > and ', but rather indicates that characters [>] ["] ['] were reflected in the parameter ID. The focus is on the vulnerability of the parameter, not the specific characters used.
B) The vulnerable parameter ID and unfiltered characters returned This choice correctly interprets the scan results by identifying that the parameter ID is vulnerable to unsafe output escaping, leading to unfiltered characters being reflected. This vulnerability could potentially be exploited for cross-site scripting (XSS) attacks.
C) Vulnerable parameters with encoded characters passed This option is inaccurate as the scan does not mention encoded characters being passed through the vulnerable parameter ID. The emphasis is on unfiltered characters being reflected, indicating a lack of proper output escaping.
D) The vulnerable parameter ID with a SQL injection attempt This answer is incorrect since the scan results do not mention any SQL injection attempts. The focus is solely on the vulnerability related to unsafe output escaping in the parameter ID, not on SQL injection vulnerabilities.
Conclusion The Nmap scan revealing unsafe output escaping in the parameter ID on the web server indicates a potential security risk where unfiltered characters can be reflected. This vulnerability could allow malicious actors to execute cross-site scripting attacks by injecting harmful scripts through the unprotected parameter. It is crucial for the security team to address and mitigate this vulnerability promptly to enhance the server's defense against such exploits.
Which of the following is the most important reason why tactics, techniques, and procedures (TTP) are beneficial to a defensive strategy?
Rationale
Understanding an attacker's strategy and behavior is crucial in developing an effective defensive strategy. By analyzing TTP, defenders can anticipate potential actions, motives, and patterns of attackers, allowing for proactive defense measures.
A) TTP provides useful insights on the hash values and internet protocol addresses attributed to an attacker. While hash values and IP addresses are important in tracking and identifying attackers, they focus more on technical aspects rather than the overarching strategy and behavior of the attacker. These details are essential for tracing attacks but do not provide insights into the attacker's broader tactics and motives.
B) TTP provides useful insights on an attacker's indicators of compromise. Indicators of compromise (IoCs) are specific pieces of information that indicate a system has been compromised. While IoCs are valuable for identifying ongoing attacks or breaches, they do not necessarily reveal the overall strategy and behavior of the attacker, which is essential for developing a comprehensive defensive strategy.
C) TTP provides useful insights on the tools used by an attacker. Understanding the tools used by an attacker is important for detecting and mitigating attacks, but it does not necessarily provide insights into the attacker's strategy and behavior. Tools alone do not reveal the intentions, tactics, or patterns of an attacker, which are essential for effective defense.
Conclusion Analyzing tactics, techniques, and procedures (TTP) is crucial for gaining insights into the strategy and behavior of an attacker. This understanding enables defenders to anticipate and counter potential threats more effectively, enhancing the overall defensive strategy. By focusing on the broader aspects of attacker behavior, defenders can develop proactive defense measures that address the root causes of attacks rather than just the technical details.
An analyst reviews a recent government alert on new zero-day threats and finds the following CVE metrics for the most critical of the vulnerabilities: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:W/RC:R. Which of the following represents the exploit code maturity of this critical vulnerability?
Rationale
The exploit code maturity level "E:U" signifies that there is an unproven exploit code, meaning that there is minimal or no proof of concept available to validate the existence of an exploit. This indicates a lower likelihood of active exploitation in the wild for this vulnerability.
A) E:U This choice correctly represents the exploit code maturity level "E:U," indicating the absence of proven exploit code for the vulnerability.
B) S:C The "S:C" metric denotes the scope of the vulnerability, specifically that it has a scope change that can impact confidentiality. This does not relate to exploit code maturity.
C) RC:R "RC:R" refers to remediation level, indicating that the vulnerability requires a vendor-provided patch or workaround for mitigation, not the exploit code maturity level.
D) AV:N "AV:N" represents the attack vector, specifying that the vulnerability can be exploited via the network. This metric does not pertain to exploit code maturity.
E) AC:L AC:L signifies the attack complexity, stating that the vulnerability can be exploited with low complexity. This metric does not address the exploit code maturity aspect.
Conclusion The correct answer is A) E:U, as it accurately reflects the exploit code maturity level associated with the critical vulnerability in question. Understanding these Common Vulnerability Scoring System (CVSS) metrics aids analysts in assessing the severity and exploitability of vulnerabilities to prioritize response actions effectively.
A security operations center analyst is using the command line to display specific traffic. The analyst uses the following command: `$ tshark -r file.pcap -Y 'http or udp'`. Which of the following will the command line display?
Rationale
The provided command instructs tshark to read the file file.pcap and display traffic matching the filter 'http or udp.' This filter will capture unencrypted web (http) requests and UDP traffic, which commonly includes DNS packets. Therefore, the displayed output will consist of unencrypted web requests and DNS traffic.
A) Encrypted web requests and Domain Name System (DNS) traffic This option is incorrect because the filter specified in the command line ('http or udp') does not target encrypted traffic. As a result, only unencrypted web requests will be captured along with DNS traffic.
C) Neither encrypted nor unencrypted web and DNS traffic This choice is incorrect as the filter 'http or udp' explicitly includes web (http) traffic and UDP packets. Therefore, the displayed output will contain unencrypted web requests and DNS traffic, not neither of them.
D) Both encrypted and unencrypted web and DNS traffic This option is incorrect because the command provided does not include a filter for encrypted traffic. The 'http or udp' filter specifically targets unencrypted web (http) traffic and UDP packets, excluding encrypted traffic. Thus, the displayed output will only include unencrypted web requests and DNS traffic.
Conclusion By utilizing the specified tshark command with the filter 'http or udp,' the security operations center analyst will view unencrypted web requests and DNS traffic from the file.pcap. This command helps in isolating and analyzing specific types of network traffic, aiding in security monitoring and incident response efforts.
A threat intelligence analyst is updating a document according to the MITRE ATT&CK framework. The analyst detects the following behavior from a malicious actor: 'The malicious actor will attempt to achieve unauthorized access to the vulnerable system.' In which of the following phases should the analyst include the detection?
Rationale
In the MITRE ATT&CK framework, tactics represent the highest level of abstraction, outlining the general objectives that an adversary aims to achieve during an attack. The behavior described, attempting unauthorized access to a vulnerable system, aligns with a strategic goal or intent of the malicious actor. Therefore, this detection should be included in the Tactics phase to provide a broad overview of the adversary's objectives.
A) Procedures Procedures in the MITRE ATT&CK framework refer to specific step-by-step instructions or processes followed by threat actors to accomplish their objectives. The behavior of attempting unauthorized access is more aligned with the strategic level of Tactics rather than the detailed operational level covered by Procedures.
B) Techniques Techniques in the MITRE ATT&CK framework are more detailed than Tactics and represent specific methods or means used by adversaries to execute their objectives. While attempting unauthorized access is an action taken by the malicious actor, it fits better within the broader strategic context of Tactics rather than the specific operational level of Techniques.
D) Subtechniques Subtechniques are the most granular level of detail in the MITRE ATT&CK framework, describing specific variations or implementations of techniques. Since the behavior described is at a higher level of abstraction related to the adversary's goal, it does not delve into the specific variations or subcategories covered by Subtechniques.
Conclusion In the context of the MITRE ATT&CK framework, the behavior of attempting unauthorized access to a vulnerable system should be categorized under Tactics. By including this detection in the Tactics phase, the threat intelligence analyst can better understand the overarching strategic objectives of the malicious actor and enhance their cybersecurity defense strategies accordingly.
Which of the following best describes root cause analysis?
Rationale
Root cause analysis involves identifying the underlying reasons for problems to prevent their recurrence by addressing the core issue directly, rather than just treating symptoms or immediate consequences.
A) It describes the tactics, techniques, and procedures used in an incident This choice does not accurately capture the essence of root cause analysis. While tactics, techniques, and procedures may be part of the investigative process, root cause analysis focuses on identifying the fundamental reason behind an issue to prevent its future manifestation.
B) It provides a detailed path outlining the origin of an issue and how to eliminate it permanently. Correct! Root cause analysis aims to delve deep into the origins of a problem, understanding the underlying causes and implementing solutions that address these root issues effectively to prevent recurrence.
C) It outlines the who-what-when-where-why, which is often used in conjunction with legal proceedings. This option confuses root cause analysis with a more general investigative framework. While understanding the who, what, when, where, and why can be part of root cause analysis, its primary focus is on identifying the fundamental cause of an issue for long-term resolution.
D) It generates a report of ongoing activities, including what was done, what is being done, and what will be done next. This description aligns more with progress reporting or project management rather than root cause analysis. Root cause analysis is specifically concerned with identifying and addressing the underlying reasons for problems.
Conclusion Root cause analysis is a systematic approach to understanding the fundamental reasons behind an issue and creating a pathway for its permanent resolution. By focusing on eliminating the root cause rather than just addressing symptoms, organizations can improve processes, enhance quality, and prevent recurrent problems.
A security operations center (SOC) manager advises the team to collaborate with other divisions and deliver a documented plan for configuring the security information and event management (SIEM) solution by the end of the week. Which of the following is the best way to accomplish this objective?
Rationale
Creating standard operating procedures (SOPs) that align the configuration of the security information and event management (SIEM) solution with established policies is crucial for ensuring consistency, efficiency, and compliance within the security operations center (SOC) environment. SOPs provide clear guidelines for team members to follow, enhancing collaboration and streamlining processes.
A) Conducting discovery for devices and organizing tasks to gather data for identifying assets While conducting device discovery and organizing tasks for asset identification are important steps in the security configuration process, they focus more on initial preparations rather than directly achieving the objective of aligning the SIEM solution configuration with policies through SOP development.
B) Storing passwords in a protected file after analysis is completed Storing passwords securely after completing analysis is a good security practice but is not directly related to configuring the SIEM solution or developing SOPs to map processes to policies. It is essential to separate password management considerations from the broader task of establishing configuration standards.
C) Developing standard operating procedures that map the processes to policies Creating SOPs that map processes to policies ensures that the configuration of the SIEM solution aligns with the overarching security objectives and compliance requirements. This approach enhances coordination, consistency, and effectiveness in implementing security measures.
D) Managing vulnerabilities to meet compliance objectives on a continuous basis While managing vulnerabilities is an essential aspect of maintaining a secure environment, focusing solely on vulnerability management does not directly address the specific objective of configuring the SIEM solution in line with policies through SOP development.
Conclusion Developing standard operating procedures that link processes to policies emerges as the most effective strategy for achieving the SOC manager's directive of configuring the SIEM solution in a documented manner by the week's end. By establishing clear procedures that reflect organizational policies, the SOC team can ensure that security configurations align with established standards and best practices, promoting a cohesive and compliant security posture.
Which of the following best explains the importance of playbooks for incident response teams?
Rationale
Having detailed and preplanned procedures in playbooks ensures that incident response teams can act swiftly and effectively in the event of security breaches or system failures, minimizing downtime, data loss, and operational disruptions.
A) Playbooks define compliance controls and help keep the monitoring process that is in place fully aligned with regulatory requirements as designed by international rules. While playbooks may incorporate compliance controls, their primary focus lies in providing specific, actionable steps for responding to incidents rather than solely ensuring regulatory alignment. Compliance considerations are typically part of a broader incident response strategy rather than the core purpose of playbooks.
B) Playbooks help implement mitigation controls to prevent the occurrence of incidents in accordance with internal policies and procedures as designed by the IT team. Playbooks primarily serve as guides for responding to incidents that have already occurred rather than focusing on preventing incidents through mitigation controls. While incident response plans may align with internal policies, playbooks are more about response actions than prevention strategies.
C) Playbooks set baseline requirements that are implemented before incidents happen to ensure the proper monitoring process in order to collect metrics and KPIs that will be used for lessons-learned procedures after a postmortem analysis. Pre-incident preparations and baseline requirements are essential components of incident response planning but are distinct from the role of playbooks. Playbooks are specifically tailored to guide actions during incidents and facilitate a structured, efficient response, rather than focusing on pre-incident monitoring or post-incident analysis.
Conclusion Playbooks serve as crucial resources for incident response teams by outlining detailed procedures to handle specific types of incidents effectively. By providing step-by-step guidance, playbooks help minimize disruptions, restore normal operations, and mitigate negative impacts on data and systems. Their emphasis on preparedness and predefined responses enhances the efficiency and effectiveness of incident response efforts, ensuring a coordinated and timely reaction to security breaches or operational failures.
A web developer reports the following error that appeared on a development server when testing a new application. Which of the following tools can be used to identify the application's point of failure?
Rationale
Immunity debugger is a powerful tool commonly used by developers to identify points of failure in applications through dynamic analysis of code execution and memory manipulation. This tool allows for in-depth examination of the application's behavior during runtime, helping pinpoint specific vulnerabilities or errors that may be causing the reported issue.
A) OpenVAS OpenVAS is a network vulnerability scanner designed to detect and assess security risks in a network environment by scanning for known vulnerabilities in systems and services. While valuable for network security assessments, OpenVAS is not tailored for identifying application-specific failures within code or memory.
B) Angry IP scanner Angry IP scanner is a lightweight, cross-platform network scanner used for discovering active hosts on a network and gathering information about them. It is primarily focused on network host discovery and IP address management, rather than diagnosing application failures or debugging software code.
D) Burp Suite Burp Suite is a comprehensive web application security testing tool used for assessing the security of web applications by analyzing their interactions and vulnerabilities. While Burp Suite is essential for web security assessments, it is not designed specifically for debugging application code or identifying points of failure within an application.
Conclusion In this scenario, the most suitable tool for identifying the point of failure in the application on the development server is Immunity debugger. By offering dynamic analysis capabilities and insights into code execution, Immunity debugger facilitates the debugging process by allowing developers to trace and analyze the application's behavior in real-time, ultimately aiding in the resolution of issues and optimization of the software.
An analyst is becoming overwhelmed with the number of events that need to be investigated for a timeline. Which of the following should the analyst focus on in order to move the incident forward?
Rationale
Focusing on the impact of events is crucial for the analyst to prioritize investigations effectively and move the incident resolution process forward. Understanding the consequences of each event allows for the allocation of resources based on the severity of potential outcomes, enabling a more efficient response strategy.
A) Impact Assessing the impact of events involves determining the severity of the consequences resulting from each incident. By prioritizing investigations based on the potential harm or disruption caused, the analyst can address critical issues first, minimizing further damage and accelerating incident resolution.
B) Vulnerability score While vulnerability scores are important for assessing system weaknesses and potential entry points for threats, focusing solely on vulnerability scores may not directly contribute to moving the incident forward. Prioritizing investigations based on impact provides a more immediate and actionable approach to addressing ongoing incidents.
C) Mean time to detect Mean time to detect is a metric that measures the average time taken to identify a security incident. While this metric is essential for evaluating the efficiency of detection processes, it does not inherently help in moving the incident forward. Understanding the impact of events is more directly linked to making informed decisions during incident response.
D) Isolation Isolating affected systems or networks is a critical step in containing the impact of security incidents. However, focusing solely on isolation may delay the overall incident resolution process if not accompanied by a clear understanding of the impact of events. Prioritizing investigations based on impact ensures a more targeted and effective response strategy.
Conclusion By prioritizing investigations based on the impact of events, the analyst can effectively manage resources, address critical issues promptly, and accelerate the incident resolution process. Understanding the consequences of each event allows for a more strategic and efficient approach to incident response, ultimately moving the investigation forward towards resolution.
An analyst is evaluating a vulnerability management dashboard. The analyst sees that a previously remediated vulnerability has reappeared on a database server. Which of the following is the most likely cause?
Rationale
When a rollback is performed on a system, changes and updates made to the software or configuration are reversed to a previous state. In the context of a database server, rolling back changes could potentially reintroduce vulnerabilities that were previously addressed through remediation efforts.
B) The finding is a false positive and should be ignored. This choice is incorrect as the scenario described involves a previously remediated vulnerability reappearing on the database server. A false positive would indicate a situation where a vulnerability is incorrectly identified when, in fact, it does not exist.
C) The vulnerability scanner was configured without credentials. While misconfigured credentials can lead to inaccurate vulnerability scanning results, in this case, the issue is related to a specific vulnerability reappearing after it was previously fixed. The cause is more likely tied to system changes rather than scanner configuration issues.
D) The vulnerability management software needs to be updated. Although keeping software up to date is crucial for security, the reappearance of a previously patched vulnerability is more likely linked to changes within the system itself, such as a rollback, rather than a deficiency in the vulnerability management software.
Conclusion In this scenario, the most likely cause of a previously remediated vulnerability reappearing on the database server is the execution of a rollback on the instance. Rollbacks can undo security patches and configurations, potentially reintroducing vulnerabilities that had been addressed. It is essential for analysts to investigate system changes, such as rollbacks, to understand why vulnerabilities resurface despite prior remediation efforts.
What would you like to do with your progress?
What would you like to do before switching?
You finished this free practice quiz.
Help us improve by flagging this content.
How helpful was this material?