Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Domains 3

Total questions: 119

Worksheet time: 1hrs 1mins

Name
Class
Date
1.

On our systems, what is the Southbridge connected to?

a)

All of these.

b)

Mouse/Keyboard.

c)

Wireless.

d)

CPU

2.

Which of these encryption methods is truly unbreakable if it is implemented right?

a)

Enigma

b)

A Vigenère cipher.

c)

Symmetric encryption.

d)

One-time pads.

3.

In our physical access control, we use gates and fences to ensure what happens.?

a)

Allow easy entry and exit from our facility.

b)

Allow easy entry and exit from our facility.

c)

Ensure entry and exit from our facility only happen through the gates.

d)

Allow employees to exit in an emergency safely.

4.

When we talk about WORM media, what are we referring to?

a)

RAM

b)

Hard disks.

c)

R DVD's.

d)

EEPROM.

5.

What handles all access between objects and subjects in the computer kernel?

a)

Reference monitor.

b)

Superuser mode.

c)

Supervisor mode.

d)

User mode.

6.

We are adding hashing to our passwords. Which of these is a hashing function we could consider?

a)

RSA

b)

DES

c)

Salting

d)

RIPEMD

7.

The NSA wanted to embed the clipper chip on all motherboards. Which encryption algorithm did the chip use?

a)

DSA

b)

Skipjack

c)

RSA

d)

3DES

8.

Which of these would be a TRUE statement about symmetric encryption?

a)

All of these.

b)

It uses private and public keys to share a session key.

c)

It is the strongest per bit.

d)

It does not use a shared key.

9.

We have seen an increasing number of viruses on our systems. As part of our defense in depth, we have implemented multiple overlapping countermeasures to mitigate the issues we have been having with viruses. Which of these are types of viruses?

(Select all that apply).

a)

Trojans

b)

Polymorphic

c)

Boot Sector.

d)

Macro

e)

Logic Bombs.

10.

We are looking at adding type 1 VM Hypervisors to our environments. What do they run on top of?

a)

The hypervisor.

b)

hardware

c)

The virtual machine.

d)

The OS.

11.

If you are faced with a fire and you need to use a fire extinguisher, which method should you use?

a)

PASS

b)

RACE

c)

PACE

d)

GASS

12.

After the Second World War the US designed and built the SIGABA. How many rotors did it use?

a)

10

b)

3

c)

15

d)

4

13.

Which type of access control model is based on a subject’s clearance?

a)

Rule-Based Access Control (RUBAC)

b)

Role-Based Access Control (RBAC)

c)

Mandatory Access Control (MAC)

d)

Discretionary Access Control (DAC)

14.

We have smoke photoelectric detectors installed in our data center. What do they detect?

a)

A rise in temperature indicating a fire.

b)

A change in the light indicating higher particle density.

c)

The infrared light emitted from a fire.

d)

If the light is off in the data center.

15.

In which of these protocols, is IPSEC built into and NOT added on later?

a)

IPv4

b)

HMAC

c)

PGP

d)

IPv6

16.

DES is very easy to break today. To remedy the problems with DES, 3DES was developed. Which of these is TRUE about 3DES K1?

a)

It is a 64-bit block cipher, with 56-bit keys.

b)

It is a 64-bit block cipher with a 128-bit key strength.

c)

It is a 128-bit block cipher with 128, 192 or 256-bit keys.

d)

It is a 64-bit block cipher with a 112-bit key strength.

17.

Using the Graham Denning model, which of these is NOT something subjects can execute on objects?

a)

Delete access.

b)

Create access.

c)

Create subject.

d)

Transfer access

18.

We have moved some of our non-critical functions to cloud hosting. We have chosen to go with an IaaS - (Infrastructure as a Service) implementation. Where would our responsibility start?

a)

C: Between virtualization and OS

b)

D. Between storage and servers

c)

A: After the application

d)

B: Between security and application

19.

Prime number factorization is an example of what?

a)

Shared key encryption.

b)

One way functions.

c)

Symmetric encryption.

d)

Two-way functions.

20.

If we have 100 users in our organization that are all needing to communicate securely with each other, would symmetric or asymmetric encryption use the highest number of encryption keys?

a)

Asymmetric

b)

They would use the same number of keys.

c)

Symmetric

d)

We would need more information to be able to tell.

21.

The order of the plaintext should be dispersed in the ciphertext. What is this called?

a)

Confusion

b)

Substitution.

c)

Diffusion

d)

Permutation

22.

When we experience a power surge, what is happening?

a)

We have a short loss of power.

b)

We have a long loss of power.

c)

We have a long low voltage period.

d)

We have a long high voltage period.

23.

What is the relationship between plaintext and ciphertext is called?

a)

Diffusion

b)

Substition.

c)

Confusion.

d)

Permutation.

24.

Which security principle is Clark-Wilson based on?

a)

Availability

b)

Confidentiality

c)

Accountability

d)

Integrity

25.

Jane is talking to a colleague about a regular computer bus. What is that connected to?

a)

CPU

b)

All of these.

c)

Mouse/Keyboard.

d)

RAM

26.

Which is the MOST secure encryption type of these 4?

a)

DES

b)

AES

c)

Blowfish

d)

RC4

27.

What is the MOST important to secure the safety of FIRST in an emergency?

a)

Critical servers.

b)

Staff

c)

Backups

d)

The building.

28.

Which of these is NOT part of our server hardening?

a)

Enable the USB drives on the servers.

b)

Blocking ports not required by the server.

c)

Disabling default user accounts.

d)

Applying all patches.

29.

With newer CPU (Central Processing Units) we can use pipelining, where each processor cycle does multiple tasks. Which of these are functions the CPU performs?

(Select all that apply).

a)

Decode.

b)

Store

c)

Combine

d)

Execute

e)

Fetch

30.

What could be a type of physical access control that we would use, to prevent cars and vans from entering our perimeter?

a)

Motion sensors.

b)

Cameras

c)

Bollards

d)

Lights

31.

Lattice-based access control uses which access control principle?

a)

Mandatory Access Control (MAC)

b)

Rule-Based Access Control (RUBAC)

c)

Role-Based Access Control (RBAC)

d)

Discretionary Access Control (DAC)

32.

When we are installing motion sensors, we are implementing which type of control?

a)

Administrative and detective.

b)

Preventative and detective.

c)

Detective and deterrence.

d)

Deterrence and preventative.

33.

Which of these would be the PRIMARY reason we would choose to use hash functions?

a)

Availability

b)

Confidentiality

c)

Authorization

d)

Integrity

34.

We have started issuing cell phones to our employees and we want a centralized way of managing them. What could be something we should consider implementing?

a)

MDM

b)

DRM

c)

AMA

d)

MGM

35.

Jack is looking at different types of encryption. Which of these is a type of asymmetric encryption?

a)

Twofish

b)

RSA

c)

RC6

d)

3DES

36.

You hear a colleague talk about polyinstantiation. What does that mean?

a)

Looking at a normal baseline and learning of new factors on the network from higher traffic.

b)

Two or more instances of the same data, depending on who accesses it.

c)

Collecting data to analyze it.

d)

Deducing facts from data rather than specific statements.

37.

What are Programmable Logic Controllers (PLCs) used for?

a)

Controlling manufacturing processes.

b)

Computerized control system for a process or plant.

c)

High-level control supervisory management.

d)

Monitor our servers, workstations, and network devices.

38.

Which of these hashing algorithms is still considered secure and collision-free?

a)

RIPEMD160

b)

MD5

c)

SHA1

d)

MD6

39.

The Central Processing Unit (CPU) consists of which two elements?

a)

RAM and BIOS.

b)

CU and RPG.

c)

ALU and CU.

d)

Southbridge and RAM.

40.

Which part of the CPU controls fetching from memory and execution of instructions?

a)

ALU

b)

ROM

c)

RAM

d)

CU

41.

BIBA's Invocation Property prohibits users from what?

a)

No write up.

b)

No read and write up and down.

c)

No write down.

d)

No read and write up.

42.

One of our engineers has found a virus on one of our systems that keeps changing the signature. What type of virus is it?

a)

Multipart.

b)

Stealth virus.

c)

Macro virus.

d)

Polymorphic

43.

If we have 5 users and they all need to communicate with each other securely, would we use the MOST encryption keys if we used asymmetric or symmetric encryption?

a)

They would use the same number of keys.

b)

Symmetric

c)

We would need more information to be able to tell.

d)

Asymmetric

44.

When we are looking at an IPSec implementation, all of these could be part of it, EXCEPT which?

a)

ESP

b)

SA

c)

DR

d)

AH

45.

When a CPU (Central Processing Unit) can execute multiple processes concurrently, it is called what?

a)

Multithreading

b)

Multitasking

c)

Multiprocessing.

d)

Multiprogramming

46.

When we are talking about the Twofish encryption algorithm, which of these is TRUE?

a)

It is a 64-bit block cipher with a 112-bit key.

b)

It is a 64-bit block cipher with a 128-bit key.

c)

It is a 128-bit block cipher with 128, 192 or 256-bit keys.

d)

It is a 64-bit block cipher, with 56-bit keys.

47.

We have, for many years, used dogs as part of our physical security. However, we are considering implementing other physical security measures and stop using dogs. Which of these could be the reason we would consider NOT using dogs more?

a)

It is expensive.

b)

They are not very good at deterring.

c)

They can cause liability issues.

d)

They are always friendly.

48.

When we are replacing one character with another, what is that called?

a)

Substitution

b)

Confusion

c)

Diffusion

d)

Permutation

49.

A historical type of encryption that was based on a set of disks with random letters; the sender and receiver would agree on the disk order. What is it called?

a)

Vigenère cipher.

b)

Spartan Scytale.

c)

Bazeries

d)

Caesar cipher.

50.

When we have our private and public keys in key escrow, what does that mean?

a)

Someone keeping a copy of our keys, often law enforcement.

b)

The public key is available to everyone.

c)

The private key I have on my system.

d)

The server we keep our public and private keys on.

51.

When, in telecommunications, we talk about the Demarc, what are we referring to?

a)

You ensure all of the other tenants have full access to your network equipment.

b)

You place all your routers and switches.

c)

The ISP terminates their line and your network begins.

d)

The servers are places to ensure faster speeds.

52.

Jane is talking to a friend and is explaining what digital signatures do. Which of these could be something that she tells her friend is one of the MAIN reasons we use digital signatures?

a)

Integrity

b)

Authentication

c)

Confidentiality

d)

Availability

53.

Depending on our implementation, we may choose to use asymmetric or symmetric encryption. Which of these are types of symmetric encryption?

(Select all that apply).

a)

Elliptic Curve Cryptography (ECC).

b)

Advanced Encryption Standard (AES).

c)

Data Encryption Standard (DES).

d)

Twofish

e)

Diffie–Hellman (DH)

54.

As part of our kickoff meeting for our IPSec implementation, Jane is asked a lot of questions by a senior manager. Which of these is something we could implement as part of our IPSec implementation?

(Select all that apply).

a)

ESP (Encapsulation Security Payload).

b)

AH (Authentication Header).

c)

CRL (Certification Revocation List).

d)

SA (Security Association).

e)

IKE (Internet Key Exchange).

55.

If we are using Mandatory Access Control (MAC) and we are looking at the BIBA's * integrity axiom, what can't we do?

a)

Write down.

b)

Read up.

c)

Read down.

d)

Write up.

56.

We are designing a new data center. Which of these if installed should ALWAYS prevent power fluctuations?

a)

CPU

b)

UPS

c)

PDU

d)

Batteries

57.

Which type of ASTM standard gate could you have at your house?

a)

Class I.

b)

Class IV.

c)

Class III.

d)

Class XI.

58.

Looking at the logical ring model, where would we find a VM hypervisor?

a)

-1

b)

3

c)

0

d)

2

59.

What can we use digital signatures to provide?

a)

Authentication

b)

Availability

c)

Non-repudiation.

d)

Confidentiality.

60.

When we are rearranging the plaintext what is it called?

a)

Diffusion

b)

Confusion

c)

Substitution

d)

Permutation

61.

When we are replacing memory sticks in a server, we should use which of these to prevent damage to hardware when handling it?

a)

Proper humidity.

b)

A dark data center.

c)

Antistatic equipment.

d)

A sharp screwdriver.

62.

We are having problems with the electricity in the area, where we have one of our data centers. What is happening when a brownout occurs?

a)

We have a long low voltage period.

b)

We have a long loss of power.

c)

We have a short loss of power.

d)

We have a long high voltage period.

63.

We are talking about implementing new encryption in our organization. Which of these would be TRUE about IDEA?

a)

It is a 64 bit block cipher with a 112 bit key.

b)

It is a 64 bit block cipher, with 56 bit keys.

c)

It is a 64 bit block cipher with a 128 bit key.

d)

It is a 128 bit block cipher with 128, 192 or 256 bit keys.

64.

We are using different types of anti-virus in our organization. Which type MUST be constantly updated?

a)

Embedded

b)

Signature

c)

Formal

d)

Heuristic

65.

Which historical type of encryption involved the sender switching letters a certain number of spots forwards or back in the alphabet, with the receiver doing the same in the opposite direction?

a)

Vigenère cipher.

b)

Spartan Scytale.

c)

Bazeries

d)

Caesar cipher.

66.

We have 100 users all needing to communicate with each other.

If we are using asymmetric encryption how many keys would we need?

a)

200

b)

4950

c)

100

d)

2000

67.

Which of these is NOT covered by the Wassenaar Arrangement?

a)

Encryption algorithms.

b)

Rockets

c)

SQL Databases.

d)

Munitions

68.

When we are using frequency analysis, what are we looking at?

a)

How often pairs of letters are used.

b)

How often messages are sent.

c)

How many messages are sent.

d)

How often certain letters are used.

69.

We are using cloud computing and have chosen to use IaaS. Who is responsible for the databases?

a)

The customer.

b)

The vendor.

c)

The security team.

d)

The network team.

70.

Which type of malware is embedded in another normal program?

a)

Worms

b)

Rootkits

c)

Trojans

d)

Logic bombs.

71.

We are implementing passive monitoring in our data center. We have chosen to use infrared motion detectors.

What do they use to detect movement?

a)

Heat

b)

Sound

c)

Light

d)

Pulses

72.

Our organization is considering acquiring one of our competitors. Before we agree to the purchase, we have done a security assessment of their facility. None of the findings were too alarming, but we want them fixed as soon as possible. To ensure we only allow authorized employees inside our fence, which of these physical security problems would you want to fix FIRST?

a)

The opening in the fence

b)

The poor lighting

c)

The locked turnstile

d)

The broken camera

73.

We are choosing a site to build a new data center and offices in. Which of these would NOT be a valid security concern?

a)

Crime in the area.

b)

Whether the area is prone to flooding.

c)

How good the utilities are.

d)

How pretty the area is.

74.

In our data center, we want to ensure proper air circulation. Where would our servers normally pull the air in from?

a)

Air ducts.

b)

Cold isles.

c)

Hot isles.

d)

Sub-flooring.

75.

The original Enigma machine was broken by the Polish in 1939. How many rotors did the Enigma use at the end of the Second World War?

a)

10

b)

5

c)

4

d)

3

76.

We are looking at implementing a new type of symmetric encryption. Which of these symmetric encryption types are no longer considered secure, and should be something we should NOT consider?

a)

AES

b)

RC4

c)

3DES K1.

d)

Twofish

77.

In which order does the CPU process work?

a)

Fetch, decode, execute, store.

b)

Execute, fetch, decode, store.

c)

Fetch, decode, store, execute.

d)

Fetch, execute, decode, store.

78.

A senior VP stops you in the cafeteria because you are one of those IT people.

She asks you questions about Public Key Infrastructure (PKI).

After you explain it at a high level, they ask for more detail. You could tell them PKI uses which of these?

a)

Hashes

b)

Symmetric encryption.

c)

All of these.

d)

Asymmetric encryption.

79.

When a computer uses more than one processor at a time for a task, it is called what?

a)

Multithreading

b)

Multitasking

c)

Multiprogramming.

d)

Multiprocessing

80.

On which layer of the ring model would we find the applications?

a)

-1

b)

3

c)

0

d)

2

81.

We have implemented different types of anti-virus throughout our organization. Which type of anti-virus can produce a lot of false positives?

a)

Heuristic

b)

Signature

c)

Formal

d)

Embedded

82.

Halon is by far the best fire suppression. It can keep hardware, employees, and our building safer by putting the fires out more efficiently.

Why is it we no longer use Halon in our fire suppression systems?

a)

It is not very good at putting fires out.

b)

It depletes the ozone layer.

c)

It damages hardware.

d)

It is too expensive.

83.

Most newer systems would have multiple Central Processing Units (CPUs). What is it called when multiple tasks share one CPU?

a)

Multiprocessing

b)

Multithreading

c)

Multiprogramming

d)

Multitasking

84.

In our data centers, we have microwave motion detectors installed. What do they use to detect movement?

a)

Sound

b)

Heat

c)

Light

d)

Pulses

85.

We use different types of fire suppression depending on where it is and what is in that location. Which areas would it be appropriate for us to use CO2 fire suppression?

a)

In all of our offices.

b)

In unmanned areas.

c)

In our data center.

d)

In the bathrooms.

86.

We have several physical security issues we are wanting to address. Which of these would you want to fix FIRST, if you needed to ensure safe employee evacuation in a disaster event?

a)

The missing fence

b)

The broken camera

c)

The broken turnstilles

d)

The functional gate

87.

We are using cloud computing, and we are responsible for the operating system and up. Which type of cloud computing are we using?

a)

Software as a Service (SaaS)

b)

Infrastructure as a Service (IaaS)

c)

IDentiry as a Service (IDaaS)

d)

Platform as a Service (PaaS)

88.

Where would you suggest we place a guard at our perimeter to ensure only authorized employees can get onto our grounds?

a)

At the gate

b)

At the building with the open door

c)

At the turnstiles

d)

N/A

89.

How many keys would we have if we had 100 users using symmetric encryption?

a)

4950

b)

2000

c)

200

d)

100

90.

In computer architecture, what would the north bridge be connected to?

a)

Mouse/Keyboard.

b)

All of these.

c)

CPU

d)

Wireless

91.

Which of these is a TRUE about hybrid encryption?

a)

It is the strongest per bit.

b)

It does not use a shared key.

c)

All of these.

d)

It uses private and public keys to share a symmetric session key.

92.

If we are using the Graham Denning model, which of these is NOT something a subject can execute on an object?

a)

Create subject.

b)

Transfer access

c)

Read subject

d)

Delete access.

93.

We are building a new data center and the walls must be slab-to-slab. What does that mean?

a)

The wall is made of slabs.

b)

The wall is from the real floor to the real ceiling.

c)

The wall is from the top of the subfloor to the subceiling.

d)

The wall is from the real floor to the sub ceiling.

94.

We are designing a new data center. At a presentation to senior management and the board of directors, you are asked: "Why do we need to keep the humidity controlled in the data center?" What should your reply be?

a)

To keep it nice in there for employees.

b)

To prevent EMI.

c)

To ensure the data is safe.

d)

To prevent corrosion on our equipment.

95.

If we are using the Bell-LaPadula *security property," what CAN'T we do?

a)

Write down.

b)

Read up.

c)

Write up.

d)

Read down.

96.

Which type of fire extinguisher would you use on a metal fire?

a)

Soda-Acid.

b)

Class A.

c)

Wet chemical.

d)

Dry powder.

97.

When we talk about using cryptanalysis in our work, what are we doing?

a)

The science of breaking encrypted communications.

b)

A cryptographic algorithm.

c)

Creates messages with a hidden meaning.

d)

The science of securing communications.

98.

Which type of American Society for Testing and Materials (ASTM) standard gate would we have on a loading dock for 18-wheeler trucks?

a)

Class IV.

b)

Class XI.

c)

Class I.

d)

Class III.

99.

What is your public key in asymmetric encryption?

a)

Used by you to decrypt messages sent to you.

b)

Secret

c)

Shared

d)

Used by someone else to decrypt messages from you.

100.

When we are implementing IPsec, we would make use of all these, EXCEPT which?

a)

ESP

b)

AH

c)

SA

d)

AV.

101.

As part of our security posture, we have deployed turnstiles at our exit point from a facility.

Which of these is a TRUE statement about turnstiles?

a)

Fail shut.

b)

Prevent exit always.

c)

Fail open.

d)

Prevent exit in an emergency.

102.

What would we use Distributed Control Systems (DSCs) for?

a)

Monitor our servers, workstations and network devices.

b)

High level control supervisory management.

c)

Computerized control system for a process or plant.

d)

Controlling manufacturing processes.

103.

We have part of our infrastructure migrated to cloud computing. We are responsible for the applications and the data.

Which type of cloud computing are we using?

a)

Infrastructure as a Service (IaaS)

b)

Software as a Service (SaaS)

c)

IDentiry as a Service (IDaaS)

d)

Platform as a Service (PaaS)

104.

If an attacker is using a digraph attack, what is the attacker looking for? ​

a)

How often pairs of letters are used.

b)

How many messages are sent.

c)

How often certain letters are used.

d)

How often messages are sent.

105.

If we are using the Bell-LaPadula "simple security property", what can't we do?

a)

Read up.

b)

Write down.

c)

Write up.

d)

Read down.

106.

What historical encryption was written on a thin piece of parchment that was wrapped around a round stick of a certain diameter?

a)

Spartan Scytale.

b)

Vigenère cipher.

c)

Bazeries

d)

Caesar cipher.

107.

Which of these countermeasures would be effective against rainbow tables?

a)

Keeping hashes in plaintext.

b)

Key stretching.

c)

Salting

d)

Limiting login attempts.

108.

Which security principle is Bell-LaPadula based on?

a)

Integrity

b)

Authentication

c)

Confidentiality

d)

Availability

109.

When would a logic bomb go off?

a)

When the system gets internet access.

b)

When it has infected the entire network.

c)

As soon as it is introduced to the system.

d)

A certain event happens or at a certain time.

110.

We have decided to change the type of hashing we use to a newer version that is collision-resistant.

What happens when a hash collision occurs?

a)

When two different plaintexts produce the same hash.

b)

You can figure out the plain text from the hash.

c)

The same plain text produces two different hashes using the same hash function.

d)

A variable-length text produces a fixed-length hash.

111.

A monolithic kernel runs in which mode?

a)

Reference monitor.

b)

Superuser mode.

c)

Supervisor mode.

d)

User mode.

112.

Which of these rotary-based encryption machines was NOT known to have been broken while it was in active use?

a)

PRAAS

b)

Enigma

c)

SIGABA

d)

Purple

113.

If we have mantraps in our environment, what should they do?

a)

Prevent exit in an emergency.

b)

Fail shut.

c)

Fail open.

d)

Prevent exit always.

114.

In which part of the computer are all the calculations done?

a)

CPU

b)

CU

c)

ALU

d)

ROM

115.

When an attacker is using a brute force attack to break a password, what are they doing?

a)

Looking at the hash values and comparing it to thousands or millions of pre-calculated hashes.

b)

Trying every possible key to, over time, break any encryption.

c)

Trying to recover the key without breaking the encryption.

d)

Looking at common letter frequency to guess the plaintext.

116.

If we want to implement a type of encryption that uses discrete logarithms, which of these could we choose?

a)

Twofish

b)

ECC

c)

DES

d)

AES

117.

The original version of the Enigma machines encryption was broken by the Polish intelligence in 1939. When it was broken in 1939, how many rotors did it use?

a)

5

b)

10

c)

4

d)

3

118.

Jane and Bob are talking about hashing and they use the abbreviation MAC. What are they talking about?

a)

Media Access Control.

b)

Message Authentication Code.

c)

Mandatory Access Control.

d)

Message Access Code.

119.

In newer computer architecture, we have split the bus into a north and a south bridge. The north bridge is much faster than the south bridge. Which of these is the north bridge?

a)

B

b)

C

c)

A

d)

All of these