WorksheetsModule 5 Test Review
Total questions: 56
Worksheet time: 29mins
What is the CIA triad?
cyber, issues, alert
confidentiality, issues, alerts
confidentiality, integrity, availability
cyber, integrity, admin
A part of the CIA triad, what is the process of ensuring that the data sent is what arrives to the intended destination
Confidentiality
Integrity
Availability
A part of the CIA triad, having access to the data we need when we need it.
Confidentiality
Integrity
Availability
A part of the CIA triad, what is the focus on making sure data transmissions are kept private
Confidentiality
Integrity
Availability
a type of confidentiality concern that is based on a violation of trust
social engineering
sniffing
snooping
dumpster diving
Data at rest being viewed by someone without given access.
eavesdropping
snooping
sniffing
dumpster diving
Which property of secure information is compromised by man in the middle?
Confidentiality
Integrity
Availibality
An attacker has used a rogue access point to intercept traffic passing between wireless clients and the wired network segment. What type of attack is this?
man in the middle
dumpster diving
replay
impersonation
What does AAA stand for?
Authentication, Authorization, Accounting
Availability, Action, Accounting
Action, Authority, Availability
A user has noticed that his email password has been compromised. This user is concerned that their social media and banking accounts are vulnerable now. Why would this be?
password reuse
snooping
phishing
social engineering
A regulation for a company is to have their finger prints scanned upon entering. Which concept is this?
authentication
accounting
integrity
confidentiality
DDos uses what to overwhelm a system?
botnets
MiM
snooping
wiretapping
Single point failures can be protected by what?
fault tolerance
authentication
accounting
authorization
How can we protect again power failures?
back ups
redundant power options
generators
redundant circuits
A company finds their trash has been ripped upon overnight. What type of concern would this be?
dumpster diving
shoulder surfing
wiretapping
snooping
A Florida business is preparing for a hurricane and needs to backup data incase of power outages and loss. What type of plan is this?
disaster recovery
business continuity
redundancy
contigency
When an exploit is found, what is used to secure it?
Patches
anti-virus
firewalls
drivers
As long as a file doesn't appear malicious, you should keep it if you are not using it.
True
False
This could allow the attacker to use the computer in a botnet, to launch ____________attacks or mass-mail spam.
DDos
social engineering
snooping
eavesdropping
What is the name of an application that appears to look like a helpful application but instead does harm to your computer?
trojan horse
worm
malware
virus
Part of host hardening is to reduce the attack surface. What configuration changes does reducing the attack surface involve?
Removing unwanted and unnecessary software
disabling unused OS features and services
shutting off the computers
keeping all applications from default
A form of malware that needs the user to trigger replication.
worm
virus
The malware encrypts the user's documents folder and any attached removable disks then extorts the user for money to release the encryption key.
What type of malware is this?
ransomware
spyware
adware
trojan horse
Most anti-virus software can remediate a system by blocking access to an infected file but not actually deleting it.
True
False
What is the main means by which anti-virus software identifies infected files?
defintions
signatures
heuristic behavior
the infected files are in purple
What are the two main ways that spam might expose recipients to hazardous content?
malware infected attachments
malicious websites
going to secure sites
Which of the following types of confidential information should be governed by classification and handling procedures?
Personally Identifiable Information (PII)
Confidential information
Passwords
Customer information
What type of control prevents a user from denying they performed an action?
Implicit deny
Non-repudiation
Least privilege
Authentication
An owner has full control over the resources of which authorized access model?
Mandatory Access Control (MAC)
Rule-based Access Control
Role-based Access Control (RBAC)
Discretionary Access Control (DAC)
Which of the following is an example of multifactor authentication?
Password and passphrase
Smart card and PIN
Fingerprint and retina scan
Hardware token and smartphone
What type of system allows a user to authenticate once to access multiple services?
Single Sign-On
Two-Factor Authentication
Windows Hello
Biometric
A user is buying a laptop. The user will have a lot of personal and confidential information on the laptop. The user wants to ensure data cannot be accessed by anyone, even if the laptop is stolen. Which of the following should be set up to accomplish this?
Permissions
Encryption
Auditing
Compression
This type of email attack appears credible as it uses legitimate information like names and email addresses to trick the user into executing it.
Spear Phishing
Phishing
Whaling
An attack with the intention to make the target system unavailable to legitimate users is called what type of attack?
Denial of Service
Ransomware
Spyware
Botnet
One of the simplest yet strongest security methods is ________.
User Education
Using Antivirus
Email Encryption
Complex Passwords
You have just created a Google account, giving you access to cloud-based services such as Google Drive, Gmail, and Google Docs to name a few. What type of authentication is used for this account?
SSO
SSL
Password Locker
Easy Passwords
Which door lock type is considered most secure?
Biometric Lock
Padlock
Combination Lock
Key Lock
Select the most secure strong password of the selections provided.
P@55_w0rD&_1492
PAssword
P@ssword
19P4ssword81
Which of the following ensures the privacy of a VPN connection?
Hashing
Tunneling
Authentication
Packet Inspection
Harmful programs used to disrupt computer operation, gather sensitive information, or gain unauthorized access to computer systems are commonly referred to as:
Adware
Malware
Ransomware
Spyware
What is the name of a standalone malicious computer program that typically propagates itself over a computer network to adversely affect system resources and network bandwidth?
Spyware
Worm
Trojan
Spam
True or False: As opposed to the simple Denial of Service (DoS) attacks that usually are performed from a single system, a Distributed Denial of Service (DDoS) attack uses multiple compromised computer systems to perform the attack against its target.
(a)
What is authentication?
Any method a computer uses to determine who or what can access it
Any method a computer uses to determine what a verified user can do
The record-keeping and tracking of user activities on a computer network
What is the purpose of Accounting?
Who can access the network?
What all can a person access on the network?
What all did the person access while on the network?
A ______ records events that occur in an OS or other software, or messages between different users of a communication software.
Cookie
Log file
Tracking
Cache
As the owner of a spreadsheet, you can determine who in your environment has read only access and who has read/write access, what is this known as?
MAC
RBAC
DAC
TAC
Which of the following is an example of a biometric reading?
Password
Iris scan
PIN
SMS token
Which of the following is a password best practice?
Do not use a password manager
Never reuse passwords
Keep the passwords simple and not complex
Never have a password expiration date
What is data that is physically stored in a digital form such as databases, spreadsheets, archives, or external storage drives?
Data in transit
Data at rest
Data in motion
Data in use
What is the term used to describe data that is in transit through networks?
Data in transit
Data in motion
Data in flight
What is private data in transit?
Data sent via email
Data sent within a private network
Data sent via SMS
Data transferred from one computer to another via USB
The part of a virus that is programmed to carry out the actions of the attack is called the _________.
vector
payload
virus
attack surface
Malware can have many _____, routes the malware takes to infect a computer, such as through email, infected websites, or USB drives.
payloads
attack surface
vectors
routes
When data is in transit (motion), it can be protected by which of the following?
SSL/TLS
IP protocol
Wifi
compression
A multifactor authentication includes two different types of information, hardware or software that identifies the approved user.
True
False
Which of the following types of password cracking matches the hash to those produced by ordinary words, or other information such as phrases, pet names, etc.?
Brute force
Rainbow table
Dictionary
Phrase
