Font size
WorksheetsCyber Security Month 2019
Total questions: 20
Worksheet time: 4hrs 58mins
What does the “https://” at the beginning of a URL denote, as opposed to "http://" (without the “s”)?
The site has special high definition
Information entered into the site is encrypted
The site is the newest version available
The site is not accessible to certain computers
None of the above
Which of the following is an example of a “phishing” attack?
Sending someone an email that contains a malicious link that is disguised to look like an email from someone the person knows
Creating a fake website that looks nearly identical to a real website in order to trick users into entering their login information
Sending someone a text message that contains a malicious link that is disguised to look like a notification that the person has won a contest
All of the above
A group of computers that is networked together and used by hackers to steal information is called a …
Botnet
Rootkit
DDoS
Operating System
Criminals access someone’s computer and encrypt the user’s personal files and data. The user is unable to access this data unless they pay the criminals to decrypt the files. This practice is called …
Botnet
Ransomware
Driving
Spam
“Private browsing” is a feature in many internet browsers that lets users access web pages without any information (like browsing history) being stored by the browser. Can internet service providers see the online activities of their subscribers when those subscribers are using private browsing?
Yes
No
Turning off the GPS function of your smartphone prevents any tracking of your phone’s location.
True
False
What kind of cybersecurity risks can be minimized by using a Virtual Private Network (VPN)?
Use of insecure Wi-Fi networks
Key-logging
Malware
Phishing attacks
To ensure your device and data remain secure and safe, when you install a new app it is good practice to
Not use too many apps as the smartphone will become less secure
Block all the app downloads and just use the standard one already on your phone
Scrutinize permission requests when using or installing smartphone apps
Someone posing as an IT tech requests information about your computer configuration. What kind of attack is this?
Insider Threat
Phishing
Social Engineering
Whaling
Within our company, IT Security is the responsibility of:
The Cyber Security Team
Corporate Security
Cafeteria Staff
Everyone
Cyber Security threats can originate from:
“Outside” the company
“Inside” the company
Both “Outside” and “Inside”
None of the above
You receive an email from a vendor that you have been in contact with previously who replied to a conversation that you had closed the loop on weeks ago. The email had an attachment that you opened but the contents of the document did not make sense. You should:
Reply to the vendor asking for more clarification
Ignore the email, it was just a mistake
Send the email to your co-worker to see if they can make sense of it
Report the email via PhishMe
You find a document at the printer with ITAR markings in the Header and Footer. You should:
Leave it in the printer. The person will be by shortly
Read the document while yours prints out
Bring the document to Corporate Security and explain the situation to them
GDMS Cyber Security Policies can be found:
On the IT Cyber Security CrossPoint Site
Nowhere, they do not exist
On HUB
In your New Hire Passport
Sending Company Proprietary information to a Personal Email address is ok if (hint, check IT-POL-4):
I get approval from my manager
I don’t get caught
It is something that I created
It is approved by IT and Corporate Security
It is ok to test out ethical hacking techniques on GDMS-C networks if (hint, check IT-POL-4):
It is for security research
It is for my program
It is approved by Corporate Security and IT Security
Never
It is ok to install software of my choice on my PC if:
My manager approves
I have an approved eSAC for Green Net use
I have an approved eSAC for Red Net use
I have admin rights on my PC
CP 07-102 is
The GD Corporate Policy for Cyber Security
The GDMS Policy on Cyber Security
The GDMS-C Cyber Security Process
Just a bunch of letters and numbers
The primary difference between "Patches" and "Vulnerabilities" (in software & hardware) is:
Vulnerabilities are weaknesses and Patches are fixes
Patches are weaknesses and Vulnerabilities are fixes
Patches and Vulnerabilities are both fixes
Patches and vulnerabilities are the same
GDMS reserves the right to monitor, collect, audit, access and inspect any data within the network in the following circumstances (hint, check IT-POL-3). Check all that apply
To collect evidence pertaining to compliance issues or validation with GDMS policies
To detect malware on devices or moving through the network
To ensure GDMS sensitive data in not being exfiltrated
To collect metrics on employee productivity
