Font size
WorksheetsCS- Data Security Level 6
Total questions: 48
Worksheet time: 24mins
hardware firewalls are built in ______
computers
routers
networks
websites
_____ spies on data that travels from the users computer
malware
spyware
virus
peekware
______ locks the user's access to data in exchange for money
beware
virus
ransomware
spyware
password attacks are done by guessing _____ passwords
pishing
numerical
common
easy
Phishing is cybercrime where an attacker sends emails that appear to be from a ______ source.
trusted
virus
known
phishing
The word malware stands for
___________ software.
Pick the missing word
malfunctioning
malformed
malignant
malicious
How can a Trojan infect your computer?
Through security loopholes
Suspicious web links
Disguised as legitimate software
Email attachments
Malware is a generic term for software that :
replicates itself and spread to other computers
hides on a computers and gathers information to pass on.
is designed to cause harm to the system it infects.
encrypts data on the system
What is ransomware?
Malware that steals your personal information
Malware that steals your money
Someone steals your computer and returns it when you pay them money
Locks your computer till you pay money
What type of malware is used to collect your browsing habits, keystrokes, usernames or passwords.
Trojan
Spyware
Virus
Adware
Ransomware
An input device that identifies a person based on the individual’s characteristics/traits (fingerprint)
Biometric scan
Biological print
Electronic footprint
Retinal scan
The illegal use of someone else's personal information (as a Social Security number) in order to obtain money or for some other personal gain
Internet fraud
Identity theft
Credit card fraud
Telemarketing schemes
The process of converting data into a code, especially to prevent unauthorized access
Program
Coding
Encryption
Algorithm
Which is a good user policy?
Patch Software regularly
Let people bring their own equipment
Remove unwanted user accounts
Let people decide what they can do
Cyber resilience policy let a company
Identify and respond to attacks appropriately
Protect user information without encyption
Stop all cyber attacks
Attack back at hackers
'Surveillance and Reconnaissance' service offer
Store big data
Find identities and data from infected computers
Capture and explore user identities and platforms on company network
provide end to end security for information interchange between networks
What is Zero day Attack?
Attack that confuses compters
Attack which breaks Brute force protection
Attacks which have never seen before, hence no patch will exist
It's a day without any attacks
What is the ISO standard for Data Security?
ISO25001
ISO26001
ISO27001
ISO37001
How to protect small companies from phising attacks
staff training
don't use computers
buy expensive firewall
outsource computer jobs
Person looking after for Network security and responsible for overall networks and data protection
Security Analyst
Chief Information Security Officer
The Boss
Network Manager
Why should you restrict user account privileges to perform their legitimate responsibilities?
Its easy to manage
Preventing them browsing network
So they don't delete files
Prevent hackers to gain easy access using privileged but compromised accounts
Name of ISO 27001 Standard is
Information Security Mangement
Cyber security Management
Cyber data security
Network security Standard
The major cyber defence weakness in a large company network is
they use external security teams who are not equally trustworthy
Big companies are exempt from GDPR rules
They don't invest enough to buy software and hardware
Large number of employees increase the risk of poor cyber practices
Website monitoring technology and policy will try to prevent
Denial of service attacks
Block Social Media Access
misconfigured firewalls
Limiting employees internet access
An excellent way of finding the source of intrusion is
Maintain detailed Network logs
ensuring the OS is up-to-date
Find employees with weak passwords
switch off computers at the end of the day
Network compromised by company employees is called
insider threat
Employee threat
Network company threat
Major threat
Why companies carry out 'Table Top' exercises?
To check how prepared they are against intrusion and role of each employee, in case of cyber attack
to check the strength of computer tables
its a ways to check latest technology
its ISO27001 requirement
Asymmetric Encryption uses
Receiver's public key to encrypt and receiver private key to decrypt
Sender's public key to encrypt and receiver private key to decrypt
Sender's public key to encrypt and senders private key to decrypt
Receiver's public key to encrypt and senders private key to decrypt
Why patching a software asap is important against cyber attacks?
When software weakness is found, hackers quickly write malwares to exploit it
Firewall works well with fully patched system
It slows the spread of the virus
Software license restrict you to patch asap
Perimeter defence gives
Early warning of intrusion attacks
as soon as they enter perimeter fence.
Prevention from Denial of service attacks
Monitor staff
physical security of the building
Honey Pot
traps intruders by creating a vulnerable server
let employees put honey on a toast
A room full of free IT equipment for staff to take home
Stop DNS attack
Antivirus makers
Sophos
IBM
Apple
HP
Heuristic detection method
Examine suspicious characters in a file
Ensure integrity of a file when transmit to another location
Loads into memory and constantly monitor programs for infection
Creates a static fingerprint of known malwares by examining a file
Checksum method
Examine suspicious characters in a file
Ensure integrity of a file when transmit to another storage location
Loads into memory and constantly monitor programs for infection
Creates a static fingerprint of known malwares by examining a file
Memory resident monitoring
Examine suspicious characters in a file
Ensure integrity of a file when transmit to another storage location
Loads into memory and constantly monitor programs for infection
Creates a static fingerprint of known malwares by examining a file
Signature based detection
Examine suspicious characters in a file
Ensure integrity of a file when transmit to another storage location
Loads into memory and constantly monitor programs for infection
Creates a static fingerprint of known malwares by examining a file
You can improve Perimeter security by using
strong passwords
Virtual Private networks (VPN's)
Internal intrusion detection system
Faking Websites to distract hackers
