wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

1002 A + Ch 04 & 05 Security Principles & Security Technologies

Total questions: 33

Worksheet time: 17mins

Name
Class
Date
1.

Ann, an end user, receives a call from someone claiming to be from the help desk and asking for her username and password to prevent her email box from being deleted immediately. Which of the following BEST describes this type of attack?

a)

Social engineering

b)

Ransomware

c)

Man-in-the-middle

d)

Shoulder surfing

2.

Which of the following is a type of security threat where a collection of infected computers is used together to deliver spam, spread malware, or other attacks?

a)

Phishing

b)

Botnet

c)

Logic bomb

d)

Man-in-the-middle

3.

Joe, a user, just downloaded a game onto his company phone. When he is not using the device, it unexpectedly dials unrecognized numbers and downloads new content. Joe is the victim of which of the following?

a)

Trojan horse

b)

Spyware

c)

Social engineering

d)

Worms

4.

A human-based or software-based attack where the goal is to pretend to be someone else for the purpose of identity concealment is ________.

a)

Social engineering

b)

Spoofing

c)

Zero-day

d)

Man-in-the-middle

5.

A user in the accounting department is not able to access a file on the network accounting folder. What is the likely reason?

a)

The workstation is victim of a denial-of-service attack

b)

The username is not authenticating on the network

c)

The user does not have file level permissions

d)

The administrator has not applied appropriate security patches

6.

A technician has been tasked with limiting the users who can connect to a network printer located centrally within an office environment. Which of the following tools would be the BEST to utilize to achieve this goal?

a)

VPN

b)

ACL

c)

RDP

d)

DLP

7.

What is the process of setting practices and procedures that govern how an organization will respond to a data security breach?

a)

Incident Management

b)

Disaster Recovery Plan

c)

Business Impact Analysis

d)

Group Security Policy Settings

8.

What controls the overall security behavior of a Windows system?

a)

User training

b)

Administrators

c)

Windows Security Policy Settings

d)

Computer Management Console

9.

Which of the following will help to protect an organization from unauthorized access to their network? (Click all that apply)

a)

Multi-factor authentication

b)

Strong passwords

c)

Physical security

10.

What is a software suite that helps protect data from being stolen while the data is moving across the network?

a)

Firewall

b)

Encryption

c)

Port Filtering

d)

DLP

11.

A turnstile is an example of which of the following forms of physical security?

a)

Mantrap

b)

Entry control roster

c)

Biometrics

d)

Cipher lock

12.

Disabling this function prevents malware and other viruses from being loaded automatically off removeable media, such as a USB flash drive.

a)

Timeout

b)

Account lockout

c)

User permissions

d)

AutoRun

13.

__________are tactical documents that specify a process to follow to meet policy requirements.

a)

Procedures

b)

Standards

c)

Security Profile

d)

Security Controls

14.

A comprehensive document that includes all of an organization’s security policies and procedures is called a _________

a)

Security profile

b)

Security Standards

c)

Security Control Document

d)

Security System

15.

A CEO of a company received an email from a bank indicating that it was imperative that the CEO respond to the email by clicking on a link. This link then downloaded malware on to their computer. What is this an example of?

a)

Worm

b)

Whaling

c)

Spyware

d)

Backdoor

16.

Implementing strategies to follow statutory laws regarding the handling of personally identifiable information is an example of what type of security control?

a)

Compliance controls

b)

Administrative controls

c)

Digital security

d)

Physical security

17.

An industry standard that sets rules to protect credit card payment processes?

a)

SOX

b)

HIPA

c)

GDPR

d)

PCI-DSS

18.

A method of maintaining the integrity of data transmitted over a network that ensures the receiver that the data has not been tampered with?

a)

BitLocker

b)

Hashing

c)

VPN

d)

EFS

19.

A hardware token is what type of multifactor authentication?

a)

Something you know

b)

Something you are

c)

Something you have

d)

Something you do

20.

Providing no access to any services on a network is an example of?

a)

Least privilege

b)

ACL

c)

General permissions

d)

Implicit deny

21.

An overarching security principle that provides multiple layers of security in case on layer fails the other can catch the threat.

a)

Defense in depth

b)

Hardening

c)

Backup security

d)

Multi-factor defense

22.

How many subtrees are there in the Windows Registry?

a)

2

b)

4

c)

5

d)

6

23.

Which of the following is an equivalent to Registry used on Windows servers and can manage things such as domains, network accounts, security policies, and more?

a)

SQL

b)

Security policy editor

c)

Active Directory

d)

Windows server 2010

24.

You are wanting to configure your network’s router to only allow certain devices to connect. Which of the following would allow this?

a)

Port forwarding

b)

MAC filtering

c)

NAT

d)

DMZ

25.

Intrusion detection/Intrusion protection devices base their ability to track anomalies based on ____or____ . (Select two)

a)

Attack signatures

b)

Rules

c)

Behavior patterns

d)

Stateful context

26.

A legacy authentication protocol that provides limited accounting capabilities?

a)

TACACS+

b)

Diameter

c)

RADIUS

d)

AAA

27.

Which of the following network security devices acts as an intermediary content filter?

a)

Proxy

b)

Firewall

c)

IDS/IPS

d)

UTM

28.

Which of the following are common threats to digital security? Select all that apply.

a)

Power failure

b)

Malware

c)

Intrusions

d)

Stolen devices

e)

Zero-day attacks

29.

Which of the following is a network-based attack which uses botnets to overwhelm a system?

a)

Phishing

b)

Smishing

c)

DDOS

d)

Man-in-the-middle

30.

Implementing a user name and password along with a pin code and thumb print is an example of ________.

a)

Multi-factor authentication

b)

Single factor authentication

c)

Two factor authentications

d)

SSO

31.

What Regulatory Compliance Policy governs health insurance coverage and protects the privacy of patient records?

a)

SOX

b)

GDPR

c)

HIPAA

d)

PCI DSS

32.

This biometric Authentication device scans blood vessels in the retina portion of the eye and requires the device to be very close to the eye to work accurately?

a)

Retinal Scanner

b)

Iris Scanner

c)

Facial Recognition Device

d)

Fingerprint Scanner

33.

Which of the security methods is not a "Physical Security" method?

a)

Mantraps

b)

Video Surveillance

c)

Domain Policies

d)

Electronic Door Locks