NEW
Font size
WorksheetsTeachCyber Unit 2 Review - Risk, Adversity, and Trust
Total questions: 16
Worksheet time: 16mins
Which statement describes the purpose of a data classification system for cybersecurity?
To select the controls needed for protection of confidentiality to “top secret” information
To meet the legal requirement for access control to Personally Identifiable Information (PII)
To identify the risks to system security and to determine the probability of occurrence
To identify information assets and protect from a loss of confidentiality, integrity and availability
Inappropriate file access to, or disclosure of, protectively marked information, whether by an adversary or accidentally, is a loss of:
Availability
Confidentiality
Integrity
Availability and Confidentiality
User error resulting in the unauthorized access to, modification of, and disclosure confidential information assets represents a loss of:
Confidentiality
Confidentiality and Integrity
Availability and Integrity
Availability
Which term refers to a circumstance or event with the potential to have an adverse effect on organizational operations?
Threat
Vulnerability
Attack
Exploit
Which term refers to a weakness in an information system, system security procedures, internal controls, or implementation?
Threat
Vulnerability
Attack
Exploit
Which term refers to an attempt that exploits a weakness and compromises system integrity, availability, or confidentiality?
Threat
Vulnerability
Attack
Exploit
Fire, flood, or an adverse weather event potentially impacting the security of information assets is known as a:
Threat
Bug
Attack
Exploit
A software bug that can cause a buffer overflow in a computer program resulting in a loss of confidentiality, integrity, or availability is known as a:
Threat
Vulnerability
Attack
Exploit
Human error resulting in a loss of confidentiality, integrity, or availability to an information resource is known as a:
Threat
Vulnerability
Attack
Exploit
Nation-state sponsored espionage activity is an example of:
Threat
Vulnerability
Attack
Exploit
Which term refers to an individual, group, organization, or government that conducts or has the intent to conduct detrimental activities?
Threat
Vulnerability
Adversary
Exploit
The process of granting access to information technology (IT) system resources only to authorized users is a primary control for:
Identification
Availability
Confidentiality
Integrity
A firewall is an example of a security control providing:
Identification
Authentication
Access Control
Risk Assessment
The comparison of cryptographic file hashes can be used as a control for:
Availability
Confidentiality
Integrity
Response
While the purpose of password complexity rules is to improve security, which statement describes a concern about the usefulness of this security measure?
Password complexity rules make it easy for brute force attacks.
Longer passwords ensure security because they cannot be cracked.
Some people may view security protocols as impediments.
Computers cannot use file hashes on complex passwords.
The process of identifying the risks to system security and determining the probability of occurrence, the resulting impact, and the additional safeguards that mitigate this impact is known as:
CIA Triad
Risk Assessment
Incident Response
Risk Matrix
