Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Security Threats and Trust Boundaries

Total questions: 20

Worksheet time: 7mins

Name
Class
Date
1.
IT security recently found a program on your co-worker's computer that apparently tracked all of the words that they typed into the computer. what kind of malware is this?
a)
Keylogger 
b)
keyblogger
c)
trojan horse
d)
keystroke virus
2.
The system administrator in your office quits unexpectedly in the middle of the day. it's quickly apparent that he changed the server password and no one knows what is it. what might you do in this type of situation?
a)
use a trojan horse to find the password
b)
Use a password cracker to find the password
c)
use social engineering to find the password
d)
delete and reinstall the server
3.
you receive an email from your bank,telling you that your account has been compromised and you need to validate your account details or else your account will be closed. you are supposed to click a link to validate your information. what is this an example of?
a)
a security breach at your bank that needs to be resolved
b)
spam
c)
ransomware
d)
Phishing
4.

Businesses, Banks, Shops, Schools and Exam Boards all keep data on you and are required to keep it safe?

a)

True

b)

False

5.

Qwerty123 is a Strong Password (i.e. not a cyber security risk)

a)

True

b)

False

6.

Detecting Vulnerabilities in a computer system/network also includes employee behaviours and procedures?

a)

True

b)

False

7.

If a website is using HTTPS it means that...

a)

Data sent and received is encrypted

b)

Data sent and received can be viewed by others

c)

Data received is encrypted

d)

Data sent is encrypted

8.

An example of something NOT a security risk or threat to a computer is:

a)

Malicious Code

b)

Authorized Access

c)

Theft

d)

System Failure

9.
Data should be backed up.....
a)
Never
b)
When you remember
c)
Regularly
d)
After an attack
10.

Which node do we trust more?

a)

Dataflow

b)

Node 1

c)

Node 3

d)

Node 2

11.

It indicates where to focus attention on where to validate data before we use it. (the answer should be in plural form, all small letters, and two words)

(a)  

12.

It simply means that you take steps to protect your software from known security threats, but also expect a malicious user to attack your system and take the appropriate measures to minimize the impact of a security vulnerability is exploited.

a)

Security Threat

b)

Security by Design

c)

Security Trust

d)

Security Control

13.

Below are some of the factors in developing a secured information system, which is not?

a)

understand potential threats

b)

create a threat model

c)

identify potential threats

d)

tampering with data

14.

A category used in understanding potential threats in systems development.

a)

STRIPE

b)

STRIDE

c)

DEAD

d)

DREAD

15.

a STRIDE category occurs when a user makes a change or initiates some action in the system but later denies performing the action and the system lacks the necessary tracking or audit logs to prove otherwise.

a)

Spoofing

b)

Tampering

c)

Elevation of Privelege

d)

Repudiation

16.

A method used in analyzing and prioritizing potential threats in systems development.

a)

STRIPE

b)

STRIDE

c)

DEAD

d)

DREAD

17.

In DREAD method, it is prioritized by asking "Is the threat easy to discover?".

a)

Exploitability

b)

Damage

c)

Discoverability

d)

Functionality

18.

In DREAD method, it is prioritized by asking "If the threat is exploited, how much damage will occur?".

a)

Exploitability

b)

Damage

c)

Discoverability

d)

Functionality

19.

A visual representation that helps in visualizing components of your system and the interactions between them.

a)

STRIDE

b)

DREAD

c)

Threat Model

d)

Data Flow Diagram

20.

Identifying and mitigating potential security threats early in your development process will save you countless hours.

a)

Correct

b)

Partly Correct

c)

False