wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

TeachCyber Unit 2 Review - Risk, Adversity, and Trust

Total questions: 16

Worksheet time: 16mins

Name
Class
Date
1.

Which statement describes the purpose of a data classification system for cybersecurity?

a)

To select the controls needed for protection of confidentiality to “top secret” information

b)

To meet the legal requirement for access control to Personally Identifiable Information (PII)

c)

To identify the risks to system security and to determine the probability of occurrence

d)

To identify information assets and protect from a loss of confidentiality, integrity and availability

2.

Inappropriate file access to, or disclosure of, protectively marked information, whether by an adversary or accidentally, is a loss of:

a)

Availability

b)

Confidentiality

c)

Integrity

d)

Availability and Confidentiality

3.

User error resulting in the unauthorized access to, modification of, and disclosure confidential information assets represents a loss of:

a)

Confidentiality

b)

Confidentiality and Integrity

c)

Availability and Integrity

d)

Availability

4.

Which term refers to a circumstance or event with the potential to have an adverse effect on organizational operations?

a)

Threat

b)

Vulnerability

c)

Attack

d)

Exploit

5.

Which term refers to a weakness in an information system, system security procedures, internal controls, or implementation?

a)

Threat

b)

Vulnerability

c)

Attack

d)

Exploit

6.

Which term refers to an attempt that exploits a weakness and compromises system integrity, availability, or confidentiality?

a)

Threat

b)

Vulnerability

c)

Attack

d)

Exploit

7.

Fire, flood, or an adverse weather event potentially impacting the security of information assets is known as a:

a)

Threat

b)

Bug

c)

Attack

d)

Exploit

8.

A software bug that can cause a buffer overflow in a computer program resulting in a loss of confidentiality, integrity, or availability is known as a:

a)

Threat

b)

Vulnerability

c)

Attack

d)

Exploit

9.

Human error resulting in a loss of confidentiality, integrity, or availability to an information resource is known as a:

a)

Threat

b)

Vulnerability

c)

Attack

d)

Exploit

10.

Nation-state sponsored espionage activity is an example of:

a)

Threat

b)

Vulnerability

c)

Attack

d)

Exploit

11.

Which term refers to an individual, group, organization, or government that conducts or has the intent to conduct detrimental activities?

a)

Threat

b)

Vulnerability

c)

Adversary

d)

Exploit

12.

The process of granting access to information technology (IT) system resources only to authorized users is a primary control for:

a)

Identification

b)

Availability

c)

Confidentiality

d)

Integrity

13.

A firewall is an example of a security control providing:

a)

Identification

b)

Authentication

c)

Access Control

d)

Risk Assessment

14.

The comparison of cryptographic file hashes can be used as a control for:

a)

Availability

b)

Confidentiality

c)

Integrity

d)

Response

15.

While the purpose of password complexity rules is to improve security, which statement describes a concern about the usefulness of this security measure?

a)

Password complexity rules make it easy for brute force attacks.

b)

Longer passwords ensure security because they cannot be cracked.

c)

Some people may view security protocols as impediments.

d)

Computers cannot use file hashes on complex passwords.

16.

The process of identifying the risks to system security and determining the probability of occurrence, the resulting impact, and the additional safeguards that mitigate this impact is known as:

a)

CIA Triad

b)

Risk Assessment

c)

Incident Response

d)

Risk Matrix