Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CSAP Final Exam

Total questions: 81

Worksheet time: 3hrs 42mins

Name
Class
Date
1.
The purpose of awareness presentations is simply to focus attention on security.
a)
true
b)
false
2.
How many minutes until a savvy user reports a phishing attack?
a)
10
b)
15
c)
5
d)
30
e)
45+
3.
Select the items that are benefits of a security awareness program.
a)
Helps reduce the number of cybersecurity incidents, thus reducing costs
b)
Increases the number of cybersecurity attacks
c)
Enforces internal cybersecurity policies/better audit results
d)
Increases compliance with regulatory standards
4.
Which is not one of the 5 NIST framework objectives?
a)
Identify
b)
Recover
c)
Respond
d)
Report
e)
Detect
5.
The SOC and CSIRT provide the same function.
a)
true
b)
false
6.

What is a VPN?

a)

A VPN is used to connect to a printer

b)

A VPN is a connection to an IP phone

c)

A VPN is used to browse the web

d)

A VPN is used to secure remote connections to an environment.

7.
A term that can be applied to any system that is connected to a network, like a laptop, mobile device, etc.
a)
Endpoint
b)
VPN
c)
USB
d)
Switch
e)
Router
8.
A hacker may leave this lying around your office in an attempt to propagate malware infections.
a)
USB Drive
b)
Floppy Disk
c)
Cell Phone
d)
HDMI Cable
e)
Website URL
9.
Two factor authentication is the same as multifactor authentication.
a)
true
b)
false
10.
What are credentials? Choose all that apply.
a)
Username
b)
Password
c)
Keys
d)
Fingerprint
e)
Iris Scan
11.
You should never use the same password twice.
a)
true
b)
false
12.
A device and/or program used to filter data as it flows across a network and to/from individual systems.
a)
Switch
b)
Computer
c)
Firewall
d)
Proxy
e)
SIEM
13.
Your default gateway address is the address of a ____________?
a)
Switch
b)
Computer
c)
Network Card
d)
Router
e)
Firewall
14.
A weakness which may be evident in a system or an environment and has the potential to be exploited by an attacker.
a)
Threat
b)
Vulnerability
c)
Unpatched Computer
d)
Router
e)
Switch
15.

The possibility that a vulnerability could be exploited (and the way in which it WOULD be exploited) is known as a threat.

a)

true

b)

false

16.
An unpatched computer system is __________?
a)
A threat.
b)
A vulnerability.
c)
An asset
d)
A liability.
17.
If a window is open and flies are buzzing outside, the flies are a __________ to uncovered food?
a)
Nuisance
b)
Threat
c)
Vulnerability
d)
Danger
18.
What is an attack vector?
a)
An attack vector is the hackers name or political affiliation.
b)
An attack vector is how the hacker finds out your systems are vulnerable to attack.
c)
An attack vector is the computer or botnet device that the hacker uses to physically attack your network.
d)
An attack vector is a path or means by which a hacker (or cracker) can gain access to a computer or network server in order to deliver a payload or malicious outcome.
e)
An attack vector's name is Victor.
19.
This requires using diverse control types - think of combining physical controls like locks, hardware from different vendors, with technical controls such as antivirus, to protect data.
a)
Layered Security
b)
Defense in Depth
c)
Offense
d)
Security
e)
Hacker controls
20.
Using a SIEM allows cybersecurity professionals to collect and analyze data from a central location.
a)
true
b)
false
21.
Which statements describe an APT? Choose all that apply.
a)
Is an attack in which a person or group gains access to a system or network for an extended period of time.
b)
The intent of these types of attacks is usually to steal data.
c)
They are often associated with nation-state actors.
d)
Generally result in serious damages and can be extremely difficult to successfully remove from an environment.
22.
Policies are generally punishable by law.
a)
true
b)
false
23.
An attacker tries to guess someone's password by trying every possible character combination.
a)
Man in the middle
b)
Credential harvesting
c)
Brute force
d)
Malware
e)
Ransomware
24.
Social engineering attacks are __________?
a)
Hacking the network
b)
Hacking the human
c)
Hacking the server
d)
Hacking the code
25.
Customized attacks on high value targets are?
a)
Phishing
b)
Vishing
c)
Smsishing
d)
Whaling
e)
Spearfishing
26.
Approximately 40 percent of all employees worldwide are engaged in their jobs.
a)
true
b)
false
27.
A cognitive bias that leads people of limited skills or knowledge to mistakenly believe their abilities are greater than they actually are.
a)
Coriolis effect
b)
Hawkins-Jackson effect
c)
Light-Wave effect
d)
Dunning-Kruger effect
28.
There is evidence that when people do increase their security measures, such as installing a firewall, they tend to engage in more risky behavior.
a)
true
b)
false
29.
As media becomes more diversified and ubiquitous, our attention spans have gotten longer.
a)
true
b)
false
30.
Which of these are included in Dr. Cialdini's six principles of persuasion? Choose all that apply.
a)
Authority
b)
Consistency
c)
Brevity
d)
Liking
e)
Reciprocity
31.
What is "the hook" as it relates to marketing?
a)
What you use in fishing.
b)
The baited promise of a story.
c)
Something you swallow.
d)
A method of communication.
32.
Telling facts about our cause is the most important thing we can do.
a)
true
b)
false
33.
This form of marketing does NOT leverage direct sales or create a new demand.
a)
Marketing Communications
b)
Market Research
c)
Content Marketing
d)
Advertising
34.
Branding encompasses all parts of building a cohesive identity and establishing a presence within a target market.
a)
true
b)
false
35.
SEO is advertising primarily using paid search or pay per click ads.
a)
true
b)
false
36.
This concentrates on using techniques that enhance natural search results to improve a website’s ranking within the search results.
a)
SEO
b)
SEM
c)
VPN
d)
HTML
e)
URL
37.
This marketing technique involves using creative designs to promote your organization’s brand in public places. Typically, this involves leveraging ones surroundings and is very budget-friendly.
a)
Social media marketing
b)
Direct marketing
c)
Database marketing
d)
Guerilla marketing
38.
Inbound marketing includes tv ads, email blasts, trade shows, print ads and cold calling customers.
a)
true
b)
false
39.
Social media marketing, SEO, SEM, and blog posts are all examples of inbound marketing
a)
true
b)
false
40.
Which of the following is NOT a step in the security awareness funnel?
a)
Attention
b)
Facts
c)
Interest
d)
Action
41.
Which of the following are marketing metrics you should be tracking?
a)
Email opens
b)
Dwell time
c)
Shares
d)
Likes
e)
All of the above
42.
A type of logo that only uses text.
a)
Trademark
b)
Copyright
c)
Wordmark
d)
Slogan
43.
A passionate brand voice is?
a)
expressive, enthusiastic, heartfelt, action-oriented
b)
irreverent, unexpected, contrarian
c)
genuine, trustworthy, engaging, direct
d)
methodical and fact based
44.
When designing a security awareness program, it should __________. Choose all that apply.
a)
fit your org's business goals
b)
fit your network provider's risk appetite
c)
fit your organizational culture
d)
fit your security org's strategy and goals
45.

Depending on your industry, you may be subject to which government requirements for security?

a)

HIPAA

b)

GLBA

c)

GDPR

d)

LADOD

46.
HIPAA is designed to provide protection for:
a)
private health information
b)
private social security information
c)
private home information
d)
private driver license information
47.
Which of the following are reasons to implement a security awareness program? Choose all that apply.
a)
Avoid FTC fines
b)
Keep good records
c)
Avoid reputation loss
d)
Reduce civil litigation
48.
Employee surveys provide __________ that helps an organization develop a security awareness program.
a)
Advertising
b)
Audit data
c)
Market research
d)
Opinions
49.
Mobile device security typically has this level of security awareness.
a)
High
b)
Medium
c)
Low
50.
Market research for a security awareness program should include the answers to which of the following questions?
a)
What are your greatest assets and where are they – data, IP, people?
b)
Who are your highest risk groups?
c)
Where is the biggest knowledge/skills gap?
d)
All of the above
51.
Management and your cybersecurity organization are the only stakeholders to include when designing your cybersecurity awareness program.
a)
true
b)
false
52.

When stakeholders understand the cybersecurity threats related their responsibilities and the countermeasures that defend against them, you have met one of the success measures.

a)

true

b)

false

53.
The RACI matrix does NOT include the following:
a)
Who is responsible
b)
Who is intelligent
c)
Who is accountable
d)
Who is consulted
e)
Who is informed
54.
Which of the following is NOT a cultural style?
a)
Caring
b)
Purpose
c)
Recreation
d)
Results
e)
Safety
55.
According to BJ Fogg: "Behavior happens when Motivation, Ability, and a Prompt come together at the same moment."
a)
true
b)
false
56.
Howard Gardner asserts that we have multiple learning styles not multiple intelligences.
a)
true
b)
false
57.
The following are included in Howard Gardner's multiple intelligences:
a)
Solitary
b)
Social
c)
Logical
d)
Verbal
e)
Community
58.
Security awareness training could be combined with other training to fill those requirements.
a)
true
b)
false
59.
Event activated learning does NOT include:
a)
A teachable moment
b)
Testing at intervals
c)
Training when errors occur
d)
Repetition
e)
Punishment
60.
To optimize event activated learning all EAL should take place at the organizational level.
a)
true
b)
false
61.
The security awareness funnel helps us provide:
a)
The right message
b)
The wrong message
c)
A message
62.
We should share our security awareness message with everyone.
a)
true
b)
false
63.
Our security awareness messages should only be shared when adverse events happen.
a)
true
b)
false
64.

An example of a just in time security awareness message is: Choose all that apply.

a)

Holidays - safe online shopping

b)

January - Security resolutions

c)

Aug - back to school security

d)

Phishing attack

65.
Failure to report a phishing attack could trigger an event driven security awareness message.
a)
true
b)
false
66.
Security awareness messages/training should NOT cover:
a)
Malware
b)
Safe browsing
c)
Mobile device security
d)
Safe emailing
e)
Operating systems training
67.
Both event activated learning and just in time learning are recommended to meet security awareness goals.
a)
true
b)
false
68.
Ends users should receive security awareness training that covers how to write secure code.
a)
true
b)
false
69.

Security awareness channels that can be used to reach stakeholders includes:

a)

Events, live and virtual

b)

Posters

c)

Gamification (leader boards)

d)

Endpoint popups

e)

All of the above

70.
A phishing program should follow this format:
a)
Baseline phish, Spear fishing, Announce phishing program, first phish
b)
Baseline phish, announce phishing program, first phish, second phish, spear phishing
c)
Install reporting, first phish, second phish, announce phishing program, punish offenders
d)
Follow up emails, phishing training program, first phish, second phish, spear phishing
71.
Two to four weeks is generally a good goal for an organization to complete basic CBT training on security awareness.
a)
true
b)
false
72.

You security awareness out plan should include:

a)

What's the story

b)

Brand establishment

c)

Details of who, what, and when

d)

All of the above

73.
"You catch more flies with honey than with vinegar" is an example of:
a)
Using the carrot approach
b)
Using the stick approach
c)
Is not relevant to security awareness training
d)
What?
74.
Should employees be fired for failed hypothetical phishing attacks?
a)
Yes
b)
No
75.
Using a "gotcha" approach as it relates to security awareness is very productive.
a)
true
b)
false
76.
KPI's are:
a)
Key performance Indicators
b)
Key program indicators
c)
Key programming interfaces
d)
Key popular indices
77.
Your security awareness program impact reports should NOT include:
a)
Phishing metrics
b)
Incident reporting
c)
Pen test results
d)
DHCP lease reports
e)
Audit results
78.
Which of the following is a disadvantage to using free tools to create and manage your security awareness program?
a)
Resources are free
b)
Lots of information available
c)
Program creation is very time consuming
d)
Customized for the organization
79.

Which of the following variables should you consider when creating a security awareness program?

a)

People

b)

Time

c)

Budget

d)

Technology

e)

All of the above

80.
When creating or purchasing a phishing simulation, which of the following is NOT important?
a)
App ease of use
b)
Number of templates
c)
Software that users have installed to access the emails
d)
Reporting
e)
Localization
81.

According to the maturity model, the goal for your security awareness program is for all stakeholders to be __________.

a)

Blisfully unaware

b)

Risk Aware

c)

Compliant

d)

Competent and practiced