Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Information Security Fundamentals

Total questions: 60

Worksheet time: 3600secs

Name
Class
Date
1.

Which element of the CIA triad deals with ensuring users only access files they need to do their job?

a)

Authorization

b)

Integrity

c)

Availability

d)

Confidentiality

2.

If a file has been altered without permission or knowledge, this violates the principle of ____.

a)

encryption

b)

integrity

c)

least privilege

d)

confidentiality

3.

What process prevents a user from denying they made changes to a file?

a)

Encryption

b)

Permissions

c)

Nonrepudiation

d)

Secure passwords

4.

Which of the following helps provide confidentiality to data?

a)

A secure password

b)

Encryption

c)

Nonrepudiation

d)

Antimalware

5.

Which security principle is violated by an attack in which users are unable to access their files?

a)

Availability

b)

Principle of least privilege

c)

Integrity

d)

Nonrepudiation

6.

Which security technique is provided by using multiple levels of protection, such as firewalls, antimalware software, and strong password policies?

a)

Integrity

b)

Nonrepudiation

c)

Defense in depth

d)

Principle of least privilege

7.

Which of the following security domains represents the weakest link in the security chain?

a)

Workstation

b)

User

c)

System

d)

LAN

8.

Which security domain secures Supervisory Control and Data Acquisition (SCADA) systems, such as a citywide electrical grid?

a)

System

b)

WAN

c)

LAN

d)

Remote Access

9.

Which of the following would be considered an IoT device?

a)

Tablet

b)

Desktop PC

c)

Video doorbell

d)

Cell phone

10.

A computer that does not have any antimalware programs installed represents a ____ to data.

a)

threat

b)

vulnerability

c)

payload

d)

time bomb

11.

A computer has been infected with malware that allows the hacker to access the computer through a backdoor from a distant location. What is the most likely example of the malware on this machine?

a)

Trojan horse

b)

Logic bomb

c)

Remote access Trojan

d)

Armored virus

12.

Which of the following describes a type of malware that is hidden inside other software?

a)

Trojan horse

b)

Worm

c)

Backdoor

d)

Rootkit

13.

Which of the following describes a type of malware that can only infect a computer after specific criteria have been met?

a)

Time bomb

b)

Logic bomb

c)

Worm

d)

Backdoor

14.

Which type of malware is designed to prevent anyone from reading the source code?

a)

Rootkit

b)

RAT

c)

Armored virus

d)

Ransomware

15.

___ is malware that prevents legitimate access to data by encrypting the data content.

a)

Drive-by-download

b)

Polymorphic

c)

Worm

d)

Ransomware

16.

The action or intent of a virus is called its ____.

a)

threat

b)

payload

c)

design

d)

strategy

17.

A user unknowingly visits a webpage that has been compromised with ransomware, which was downloaded to the user’s device. This is an example of a ____.

a)

vulnerability

b)

crypto-infection

c)

drive-by-download

d)

nonrepudiation process

18.

Which type of malware renders a computer infected before the operating system is even loaded into memory?

a)

Ransomware

b)

Rootkit

c)

Armored virus

d)

Polymorphic virus

19.

Microsoft documents can be easily compromised by ____.

a)

time bombs

b)

ransomware

c)

rootkits

d)

macro viruses

20.

Which of the following describes an update from a software vendor that can help prevent vulnerabilities?

a)

Patch

b)

Heuristic methodology

c)

Firmware

d)

Upgrade

21.

A(n) ____ exists in software when it was released and remains unknown until it is exploited by hackers.

a)

adware

b)

bug

c)

zero-day vulnerability

d)

weak app

22.

Which of the following is a true statement?

a)

Updated antimalware programs always find the latest threats on a system.

b)

Opening e-mail attachments is a common attack vector for malware.

c)

USB drives are no longer vulnerable to malware infection.

d)

Heuristic analysis of systems can find only previously known viruses or threats.

23.

A ____ cookie remains on your computer until the expiration date is reached.

a)

session

b)

persistent

c)

third-party

d)

super

24.

A ____ cookie is deleted when the user’s web browser is closed.

a)

session

b)

shopping

c)

persistent

d)

third-party

25.

____ refers to using a lie or scam to obtain private information.

a)

Digital footprint

b)

Public records

c)

Pretexting

d)

Dumpster diving

26.

Which best describes the results of the following search-engine query:

World cup soccer -England

a)

Search results show only world-cup soccer links to the England team

b)

Search results show world-cup soccer prioritizing links for the England team

c)

Search results show world-cup soccer omitting references to the England team

d)

Search results show world-cup soccer deprioritizing links to the England

27.

Which of the following will provide the best search results for information on rootkits on Symantec’s website?

a)

Allintitle:Symantec +rootkit

b)

Site:Symantec.com “rootkit”

c)

cache:rootkit +Symantec

d)

Filetype:pdf “Symantec rootkit”

28.

Which legislation covers data protection through wire and electronic transmissions of data?

a)

CFAA

b)

ECPA

c)

HIPAA

d)

SOX

29.

With which law must a security analyst working for a bank be familiar?

a)

HIPAA

b)

CFAA

c)

PCI DSS

d)

GLBA

30.

PCI DSS applies to which type of businesses?

a)

Any business that accepts credit card transactions

b)

Organizations that are publicly traded

c)

Organizations that submit data through the Internet

d)

Organizations that deal with financial information

31.

Obtaining information as it is typed is a characteristic of a ____.

a)

worm

b)

keylogger

c)

polymorphic virus

d)

macro virus

32.

Which is a true statement regarding adware?

a)

Adware is always malware.

b)

Adware is never malware.

c)

Adware often results in pop-up advertisements.

d)

Adware runs on a computer without the user’s consent.

33.

Which of the following is a true statement?

a)

A computer without an antimalware program installed is considered a system threat.

b)

A computer without an antimalware program installed is considered a system vulnerability.

c)

A computer without an antimalware program installed is considered hacked.

d)

A computer without an antimalware program installed has been exploited.

34.

Which law protects electronic medical records and personal health information?

a)

SOX

b)

PCI DSS

c)

HIPAA

d)

ECBA

35.

A(n) ____ is a device that captures phone numbers and related information on outgoing phone calls.

a)

ECPA

b)

pen register

c)

keylogger

d)

Trojan horse

36.

Which is the primary reason to use cookies?

a)

To remember settings for users when returning to the site

b)

To place malware on computers

c)

To track every website a user opens

d)

To provide clues to a user’s actions on their computer

37.

A ____ occurs when an antimalware program identifies a file as malware, but the file is a valid, nonmalicious file.

a)

false positive

b)

false negative

c)

true positive

d)

true negative

38.

Self-replicating malware is known as a ____.

a)

rootkit

b)

worm

c)

macro virus

d)

logic bomb

39.

Which of the following search queries will allow you to search the Internet for hardware-specific keyloggers with the best result?

a)

keylogger -hardware

b)

Site:hardware keylogger

c)

keylogger +hardware

d)

keylogger -software +hardware

40.

Which type of shredder is the best defense against dumpster diving?

a)

strip-cut shredder

b)

cross-cut shredder

c)

micro-cut shredder

d)

mini-cut shredder

41.

Which of these is not a law instituted by the United States government?

a)

Sarbanes-Oxley

b)

PCI DSS

c)

GLBA

d)

HIPAA

42.

Which of these statements is not true regarding the CIA triad and its implementation?

a)

Protecting a password is done through principles in the Confidentiality portion of the CIA triad.

b)

A historical record of changes cannot be refused or denied is a principle of the Availability portion of the CIA triad.

c)

Ransomware violates the principle of Availability.

d)

A hash can determine if a file’s contents changed from its original content.

43.

Which of these legal regulations requires publicly traded companies to ensure data is not hidden, deleted, or altered?

a)

SOX

b)

GLBA

c)

CFAA

d)

ECPA

44.

Which security domain implements policies regarding security measures for network switches?

a)

WAN

b)

Workstation

c)

System

d)

LAN

45.

A virus that continuously changes its characteristics to avoid detection is called a(n) ____ virus.

a)

armored

b)

stealth

c)

polymorphic

d)

Trojan horse

46.

Which of the following is true about a ransomware attack? (Choose 2)

a)

The data is altered.

b)

The data is removed from the computer.

c)

The CIA principle of Availability is violated.

d)

Data is locked with an encryption process.

e)

The data owner’s permissions were removed from the computer.

47.

Which statements represent elements of the three aspects of the CIA security triad? (Choose 3)

a)

Data should be protected with a need-to-know mentality.

b)

All data should be password protected.

c)

Data should only be changed by authorized users.

d)

A ransomware attack is an example of preventing legitimate access to data.

e)

Permissions should be given to department managers to ensure data access.

48.

Which is true regarding a secure cookie? (Choose 2)

a)

The cookie contents are encrypted.

b)

The cookie can only be sent with https.

c)

The cookie can only be sent with http.

d)

The cookie can be sent with http or https.

49.

This malware continually changes its characteristics to avoid detection.

a)

Polymorphic virus

b)

Time Bomb

c)

Macro virus

d)

Rootkit

e)

Worm

50.

Malware in which the payload is delivered only on a specific date and possibly at a specific point on that day

a)

Time Bomb

b)

Macro virus

c)

Rootkit

d)

Worm

e)

Logic Bomb

51.

Type of malware that inserts snippets of code inside Microsoft Office type files.

a)

Logic Bomb

b)

Worm

c)

Rootkit

d)

Macro virus

e)

Polymorphic virus

52.

Malware type that is potentially very destructive, provides unlimited access to a computer from a remote location, and is very difficult to remove

a)

Macro virus

b)

Worm

c)

Rootkit

d)

Logic Bomb

e)

Polymorphic virus

53.

Malware that spreads very rapidly on a network

a)

Logic Bomb

b)

Worm

c)

Rootkit

d)

Macro virus

e)

Polymorphic virus

54.

Specific conditions or configurations must exist before this malware is executed

a)

Time Bomb

b)

Logic Bomb

c)

Worm

d)

Rootkit

55.

Security domain that includes a policy that instructs employees to lock their computer when leaving their workstation

a)

System

b)

LAN

c)

WAN

d)

Workstation

e)

Users

56.

Domain detailing IoT devices, printers, tablets and related security policies

a)

Workstation

b)

WAN

c)

LAN

d)

Users

57.

Policies related to users that work from home would be covered in this domain

a)

System

b)

LAN

c)

WAN

d)

Remote Access

e)

Users

58.

Domain that includes policies that have password and other security settings to the company’s internal routers and switches

a)

WAN

b)

LAN

c)

System

d)

Workstation

59.

Security domain that addresses firewall settings and rules

a)

WAN

b)

LAN

c)

Workstation

d)

System

60.

Domain in which security settings that cover web servers would be addressed

a)

LAN

b)

WAN

c)

System

d)

Workstation