wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Module 5 Test Review

Total questions: 56

Worksheet time: 29mins

Name
Class
Date
1.

What is the CIA triad?

a)

cyber, issues, alert

b)

confidentiality, issues, alerts

c)

confidentiality, integrity, availability

d)

cyber, integrity, admin

2.

A part of the CIA triad, what is ​the process of ensuring that the data sent is what arrives to the intended destination

a)

Confidentiality

b)

Integrity

c)

Availability

3.

A part of the CIA triad, having access to the data we need when we need it.

a)

Confidentiality

b)

Integrity

c)

Availability

4.

A part of the CIA triad, what is the focus on making sure data transmissions are kept private

a)

Confidentiality

b)

Integrity

c)

Availability

5.

a type of confidentiality concern that is based on a violation of trust

a)

social engineering

b)

sniffing

c)

snooping

d)

dumpster diving

6.

Data at rest being viewed by someone without given access.

a)

eavesdropping

b)

snooping

c)

sniffing

d)

dumpster diving

7.

Which property of secure information is compromised by man in the middle?

a)

Confidentiality

b)

Integrity

c)

Availibality

8.

An attacker has used a rogue access point to intercept traffic passing between wireless clients and the wired network segment. What type of attack is this?

a)

man in the middle

b)

dumpster diving

c)

replay

d)

impersonation

9.

What does AAA stand for?

a)

Authentication, Authorization, Accounting

b)

Availability, Action, Accounting

c)

Action, Authority, Availability

10.

A user has noticed that his email password has been compromised. This user is concerned that their social media and banking accounts are vulnerable now. Why would this be?

a)

password reuse

b)

snooping

c)

phishing

d)

social engineering

11.

A regulation for a company is to have their finger prints scanned upon entering. Which concept is this?

a)

authentication

b)

accounting

c)

integrity

d)

confidentiality

12.

DDos uses what to overwhelm a system?

a)

botnets

b)

MiM

c)

snooping

d)

wiretapping

13.

Single point failures can be protected by what?

a)

fault tolerance

b)

authentication

c)

accounting

d)

authorization

14.

How can we protect again power failures?

a)

back ups

b)

redundant power options

c)

generators

d)

redundant circuits

15.

A company finds their trash has been ripped upon overnight. What type of concern would this be?

a)

dumpster diving

b)

shoulder surfing

c)

wiretapping

d)

snooping

16.

A Florida business is preparing for a hurricane and needs to backup data incase of power outages and loss. What type of plan is this?

a)

disaster recovery

b)

business continuity

c)

redundancy

d)

contigency

17.

When an exploit is found, what is used to secure it?

a)

Patches

b)

anti-virus

c)

firewalls

d)

drivers

18.

As long as a file doesn't appear malicious, you should keep it if you are not using it.

a)

True

b)

False

19.

This could allow the attacker to use the computer in a botnet, to launch ____________attacks or mass-mail spam.

a)

DDos

b)

social engineering

c)

snooping

d)

eavesdropping

20.

What is the name of an application that appears to look like a helpful application but instead does harm to your computer?

a)

trojan horse

b)

worm

c)

malware

d)

virus

21.

Part of host hardening is to reduce the attack surface. What configuration changes does reducing the attack surface involve?

a)

Removing unwanted and unnecessary software

b)

disabling unused OS features and services

c)

shutting off the computers

d)

keeping all applications from default

22.

A form of malware that needs the user to trigger replication.

a)

worm

b)

virus

23.

The malware encrypts the user's documents folder and any attached removable disks then extorts the user for money to release the encryption key.

What type of malware is this?

a)

ransomware

b)

spyware

c)

adware

d)

trojan horse

24.

Most anti-virus software can remediate a system by blocking access to an infected file but not actually deleting it.

a)

True

b)

False

25.

What is the main means by which anti-virus software identifies infected files?

a)

defintions

b)

signatures

c)

heuristic behavior

d)

the infected files are in purple

26.

What are the two main ways that spam might expose recipients to hazardous content?

a)

malware infected attachments

b)

malicious websites

c)

going to secure sites

27.

Which of the following types of confidential information should be governed by classification and handling procedures?

a)

Personally Identifiable Information (PII)

b)

Confidential information

c)

Passwords

d)

Customer information

28.

What type of control prevents a user from denying they performed an action?

a)

Implicit deny

b)

Non-repudiation

c)

Least privilege

d)

Authentication

29.

An owner has full control over the resources of which authorized access model?

a)

Mandatory Access Control (MAC)

b)

Rule-based Access Control

c)

Role-based Access Control (RBAC)

d)

Discretionary Access Control (DAC)

30.

Which of the following is an example of multifactor authentication?

a)

Password and passphrase

b)

Smart card and PIN

c)

Fingerprint and retina scan

d)

Hardware token and smartphone

31.

What type of system allows a user to authenticate once to access multiple services?

a)

Single Sign-On

b)

Two-Factor Authentication

c)

Windows Hello

d)

Biometric

32.

A user is buying a laptop. The user will have a lot of personal and confidential information on the laptop. The user wants to ensure data cannot be accessed by anyone, even if the laptop is stolen. Which of the following should be set up to accomplish this?

a)

Permissions

b)

Encryption

c)

Auditing

d)

Compression

33.

This type of email attack appears credible as it uses legitimate information like names and email addresses to trick the user into executing it.

a)

Spear Phishing

b)

Phishing

c)

Whaling

34.

An attack with the intention to make the target system unavailable to legitimate users is called what type of attack?

a)

Denial of Service

b)

Ransomware

c)

Spyware

d)

Botnet

35.

One of the simplest yet strongest security methods is ________.

a)

User Education

b)

Using Antivirus

c)

Email Encryption

d)

Complex Passwords

36.

You have just created a Google account, giving you access to cloud-based services such as Google Drive, Gmail, and Google Docs to name a few. What type of authentication is used for this account?

a)

SSO

b)

SSL

c)

Password Locker

d)

Easy Passwords

37.

Which door lock type is considered most secure?

a)

Biometric Lock

b)

Padlock

c)

Combination Lock

d)

Key Lock

38.

Select the most secure strong password of the selections provided.

a)

P@55_w0rD&_1492

b)

PAssword

c)

P@ssword

d)

19P4ssword81

39.

Which of the following ensures the privacy of a VPN connection?

a)

Hashing

b)

Tunneling

c)

Authentication

d)

Packet Inspection

40.

Harmful programs used to disrupt computer operation, gather sensitive information, or gain unauthorized access to computer systems are commonly referred to as:

a)

Adware

b)

Malware

c)

Ransomware

d)

Spyware

41.

What is the name of a standalone malicious computer program that typically propagates itself over a computer network to adversely affect system resources and network bandwidth?

a)

Spyware

b)

Worm

c)

Trojan

d)

Spam

42.

True or False: As opposed to the simple Denial of Service (DoS) attacks that usually are performed from a single system, a Distributed Denial of Service (DDoS) attack uses multiple compromised computer systems to perform the attack against its target.

(a)  

43.

What is authentication?

a)

Any method a computer uses to determine who or what can access it

b)

Any method a computer uses to determine what a verified user can do

c)

The record-keeping and tracking of user activities on a computer network

44.

What is the purpose of Accounting?

a)

Who can access the network?

b)

What all can a person access on the network?

c)

What all did the person access while on the network?

45.

A ______ records events that occur in an OS or other software, or messages between different users of a communication software.

a)

Cookie

b)

Log file

c)

Tracking

d)

Cache

46.

As the owner of a spreadsheet, you can determine who in your environment has read only access and who has read/write access, what is this known as?

a)

MAC

b)

RBAC

c)

DAC

d)

TAC

47.

Which of the following is an example of a biometric reading?

a)

Password

b)

Iris scan

c)

PIN

d)

SMS token

48.

Which of the following is a password best practice?

a)

Do not use a password manager

b)

Never reuse passwords

c)

Keep the passwords simple and not complex

d)

Never have a password expiration date

49.

What is data that is physically stored in a digital form such as databases, spreadsheets, archives, or external storage drives?

a)

Data in transit

b)

Data at rest

c)

Data in motion

d)

Data in use

50.

What is the term used to describe data that is in transit through networks?

a)

Data in transit

b)

Data in motion

c)

Data in flight

51.

What is private data in transit?

a)

Data sent via email

b)

Data sent within a private network

c)

Data sent via SMS

d)

Data transferred from one computer to another via USB

52.

The part of a virus that is programmed to carry out the actions of the attack is called the _________.

a)

vector

b)

payload

c)

virus

d)

attack surface

53.

Malware can have many _____, routes the malware takes to infect a computer, such as through email, infected websites, or USB drives.

a)

payloads

b)

attack surface

c)

vectors

d)

routes

54.

When data is in transit (motion), it can be protected by which of the following?

a)

SSL/TLS

b)

IP protocol

c)

Wifi

d)

compression

55.

A multifactor authentication includes two different types of information, hardware or software that identifies the approved user.

a)

True

b)

False

56.

Which of the following types of password cracking matches the hash to those produced by ordinary words, or other information such as phrases, pet names, etc.?

a)

Brute force

b)

Rainbow table

c)

Dictionary

d)

Phrase