WorksheetsCyber Security
Total questions: 25
Worksheet time: 13mins
What security implementation principle is used for
granting users only the rights that are necessary for
them to perform their work? (Information Security &
Risk Management Domain) a) Discretionary
Access
Least Privilege
Mandatory Access
Separation of Duties
In mandatory access control, what determines the assignment of data classifications? (Information Security & Risk Management Domain)
The analysis of the users in conjunction with the audit department
The assessment by the information security department
The user’s evaluation of a particular information element
A security classification policy / guideline
Systemic risk the risk of
Failure of a bank, which is not adhering to regulations
Failure of two banks simultaneously due to bankruptcy of one bank
Where a group of banks fail due to contagion effect
Failure of entire banking system
As a security manager, how would you explain the primary goal of a security awareness program to senior management? (Information Security & Risk Management Domain)
Provide a vehicle for communicating security procedures
Provide a clear understanding of potential risk and exposure
Provide a forum for disclosing exposure and risk analysis
Provide a forum to communicate user responsibilities
Which statement below most accurately reflects the goal of risk mitigation? (Information Security & Risk Management Domain)
Defining the acceptable level of risk the organization can tolerate, then reduce risk to that level.
Analyzing and removing all vulnerabilities and threats to security within the organization.
Defining the acceptable level of risk the organization can tolerate, and assigning any costs associated with loss or disruption to a third party such as an insurance carrier.
Analyzing the effects of a business disruption and preparing the company’s response.
Which of the following are the Cyber crimes ?
1). Cyber crimes against persons.
2) . Cyber crimes against property.
3). Cyber crimes against government.
4). Cyber crimes against animal?
1, 2, 3 only
2, 3, 4 only
1, 3, 4 only
2, 3 only
The kind of crime involves altering raw data just before the computer processes it and then changing it back after the processing is completed_____
Data diddling
Data tampering
Salami attacks
None of above
As a security manager, how would you explain the primary goal of a security awareness program to senior management? (Information Security & Risk Management Domain)
Provide a vehicle for communicating security procedures
Provide a clear understanding of potential risk and exposure
Provide a forum for disclosing exposure and risk analysis
Provide a forum to communicate user responsibilities
As an information systems security manager (ISSM), how would you explain the purpose a system security policy? (Information Security & Risk Management Domain)
A definition of the particular settings that have been determined to provide optimum security
A set of brief, high-level statements that defines what is and is not permitted during the operation of the system
A definition of those items that must be excluded on the system
A listing of tools and applications that will be used to protect the system
A transaction where financial securities are issued against the cash flow generated from a pool of assets is called
Securitization
Credit Default Swaps
Credit Linked Notes
Total Return Swaps
What are the two basic types of attacks ?
Active
Passive
DoS
Both 1 & 2
What is the punishment in India for stealing computer documents, assets or any software’s source code from any organization, individual, or from any other means?
6 months of imprisonment and a fine of Rs. 50,000
1 year of imprisonment and a fine of Rs. 100,000
2 years of imprisonment and a fine of Rs. 250,000
3 years of imprisonment and a fine of Rs. 500,000
Download copy, extract data from an open system done fraudulently is treated as _________
cyber-warfare
cyber-security act
data-backup
Cyber-crime
_____________ is a code injecting method used for attacking the database of a system / website.
HTML injection
SQL Injection
Malicious code injection
XML Injection
Which of this is an example of physical hacking?
Remote Unauthorised access
Inserting malware loaded USB to a system
SQL Injection on SQL vulnerable site
DDoS (Distributed Denial of Service) attack
___________ is a violent act done using the Internet, which either threatens any technology user or leads to loss of life or otherwise harms anyone in order to accomplish political gain.
Cyber-warfare
Cyber campaign
Cyber-terrorism
Cyberattack
If anyone publishes sexually explicit type digital content, it will cost that person imprisonment of _________ years.
2
3
4
5
Cyber-laws are incorporated for punishing all criminals only
True
False
Which of the following is not a type of cyber crime?
Data theft
Forgery
Damage to data and systems
Installing antivirus for protection
Which of the following is not done by cyber criminals?
Unauthorized account access
Mass attack using Trojans as botnets
Email spoofing and spamming
Report vulnerability in any system
What is Firewall?
firewalls are network based security measures that control the flow of incoming and outgoing traffic
firewall is a program that encrypts all programs that access the internet
a firewall is a program that keeps other programs from using the internet
firewall are the interrupts that automatically disconnect from the internet when a threat appears.
VPN is abbreviated as __________
Visual Private Network
Virtual Protocol Network
Virtual Private Network
Virtual Protocol Networking
BitLocker is available in the _____ operating system.
Mac
Linux
Windows
Android
______________ is an internet scam done by cybercriminals where the user is convinced digitally to provide confidential information.
Phishing attack
DoS attack
Website attack
MiTM attack
Which type of hacker represents the highest risk to your network?
Black-hat hackers
Grey-hat hackers
Script kiddies
Disgruntled employees
