wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

601 Uc 12192022

Total questions: 70

Worksheet time: 37mins

Name
Class
Date
1.

Which of the following is a proprietary wireless standard maintained by Silicon Labs and supports throughput up to 40 kbps over distances of 10-100m between nodes?

a)

Z-Wave

b)

CAN bus

c)

NB-IoT 

2.

What kind of policy governs the removal of sensitive data and credentials when a user device is no longer used for company business?

a)

Offboarding

b)

Storage segmentation

c)

Onboarding

d)

Asset tracking

3.

You’ve been asked to provide security advice for a custom-robotics project using an off-the-shelf single-board computer and a specialized Linux operating system. What technology should you research first?

a)

RTOS

b)

Raspberry Pi

c)

Arduino

d)

FPGA

4.

What connection type is very similar to Bluetooth but used by more specialized devices, such as sensors and fitness trackers?

a)

SATCOM

b)

NFC

c)

GSM

d)

ANT

5.

Which of the following are essential security steps on all mobile devices?

Each correct answer represents a complete solution. Choose two.

a)

Using biometric authentication

b)

Installing a firewall app

c)

Configuring antivirus software

d)

Regularly applying operating system updates

e)

Configuring remote backup features

6.

Which of the following key management solutions would be best for a multinational organization with a strong multi-cloud presence?

a)

HSM

b)

HSMaaS

c)

Key escrow

d)

KMS

7.

Which of the following is an integrated circuit with a logical structure that can be reprogrammed after manufacture, in contrast to the pre-printed logic functions found in a microprocessor or ASIC?

a)

IoT

b)

RTOS

c)

FPGA 

d)

SoC

8.

Which Windows encryption tool can protect the entire system volume?

a)

Encrypting File System (EFS)

b)

BitLocker

c)

The attrib . +r command

d)

Both BitLocker and EFS

9.

What connection type is very similar to Bluetooth but is used by more specialized devices?

a)

RFID

b)

ANT+

c)

GPS

d)

NFC

10.

What kind of policy governs a set process for how an employee needs to prepare a device to join the program?

a)

Offboarding 

b)

Onboarding

c)

Storage segmentation

d)

Asset tracking

11.

Question 11 :Mark wants to securely erase the contents of a tape used for backups in his organization's tape library. What is the fastest secure erase method will he use that will allow the tape to be reused?

a)

Burn the tape. 

b)

Incinerate the tape.

c)

Wipe the tape by writing a random pattern of 1s and 0s to it.

d)

Use a degausser.

12.

In which of the following can the employee choose between a list of devices the company has approved for security features and support?

a)

Asset tracking

b)

CYOD

c)

GPS

d)

BYOD

13.

Which standard do you need to use when handling credit card data?

a)

NIST

b)

HIPAA

c)

PKI

d)

PCI DSS

14.

What potential security risk does an SD card pose that a USB flash drive does not?

a)

Data exfiltration

b)

Wireless attacks

c)

Photographs of sensitive areas

d)

Malware

15.

Question 15 :Privacy-enhancing technologies are part of a larger principle by which the amount of PII, PHI, or other sensitive private data that is collected and stored is carefully limited. What is the "umbrella" term under which many other terms regarding privacy enhancement fall?

a)

Data minimization

b)

Anonymization

c)

Tokenization

d)

Data masking

16.

Which of the following technologies helps to control what information can be exfiltrated from internal users and systems and what form such data can take?

a)

HSM

b)

FDE

c)

DLP

d)

TPM

17.

What was the first version of Windows to include real-time antivirus scanning?

a)

Windows Vista

b)

Windows XP Service Pack 2

c)

Windows 8

d)

Windows 7

18.

You are developing an application for sale to the public. You want to assure your users that the application they receive actually came from you. What technique will you use to provide this assurance?

a)

HIDS

b)

Trusted hardware

c)

Code signing

d)

Firewall

19.

What kind of malware can spread through a network without any human interaction?

a)

Trojan horse

b)

PUP

c)

Worm

d)

Virus

20.

Among the options listed, which mitigation technique is known most for increasing security at the expense of flexibility?

a)

SOAR

b)

Application whitelisting

c)

Application blacklisting

d)

MDM

21.

Which of the following environments is a prime vector for fileless malware in a Windows environment?

a)

Macros

b)

PowerShell

c)

Python

d)

Bash

22.

Crypto-malware is a type of what sort of malware?

a)

Keylogger

b)

Trojan

c)

Rootkit

d)

Ransomware 

23.

In terms of data governance policies, what is the relationship between the terms data custodian and data steward?

a)

The data owner performs the role of data custodian, but the data steward is a different employee.

b)

There is no functional difference in the roles based on these terms, but different organizations prefer one over the other.

c)

The custodian is interested in the technical nature of data security, while the steward is focused on its value, usefulness, and compliance to standards

d)

The custodian has sole "custody" of, or access to, the data, while the steward ensures that the data is placed where only the custodian can access it.

24.

A company decides to invest in embedded systems to improve security by limiting the number of components used in various critical and sensitive systems. Which of the following would make it more difficult to justify embedded systems in certain cases?

a)

Rejecting the use of FPGAs

b)

The decision to interface with external cryptographic modules

c)

The wireless networking range

d)

The fact that an entire system is placed on a single chip

25.

It has come to your attention that a newly created sensitive document is making the rounds among authorized users in the company. Which enterprise utility can you adjust the configuration of to reduce the likelihood that the document will fall into the wrong hands in a readable format?

a)

SSL decryptor

b)

Firewall

c)

MDM

d)

DLP

26.

What kind of malware replicates itself by exploiting system vulnerabilities?

a)

Trojan horse

b)

Logic bomb

c)

Worm

d)

Virus 

27.

What data management model assists professionals in decision making with regard to the creation of policy based on the convergence of data security and privacy, focusing on such aspects as to how it's attained and classified, how it's used and stored, and how it's archived and destroyed?

a)

An impact assessment

b)

The information life cycle

c)

Public notifications and disclosures

d)

Privacy-enhancing technologies

28.

Which of the following is a form of ransomware?

a)

Crypto-malware

b)

Rootkit

c)

Command and control

d)

Bot

29.

The VP of human resources has put you in charge of securing a critical server for the department. You’ll be hardening its operating system according to company policies and regularly checking configuration and system logs. In asset management terms, what role have you taken on?

a)

Custodian

b)

User

c)

Owner

d)

Administrator

30.

Which privacy-enhancing technology cannot be reversed and, yet, has the distinguishing capability of either replacing private data in the database or retaining it and replacing it only when each record is read from the database, usually while keeping the format and structure of the fields it impacts?

a)

Data masking

b)

Tokenization

c)

Pseudo-anonymization

d)

Anonymization

31.

What technology uses the TPM to store hashes of signed boot files for comparison the next time the system boots and for export in a quote for remote attestation?

a)

Secure boot

b)

UEFI

c)

Boot attestation

d)

Measured boot

32.

A user complains that every time they open their Internet browser, it no longer goes to their preferred home page, and advertisements pop up in dialog boxes that they have to close. What is the likely cause?

a)

Virus

b)

Trojan

c)

Spyware

d)

Worm

33.

What cryptographic tool is commonly built into a motherboard?

a)

FDE

b)

TPM

c)

HSM

d)

DLP

34.

Your organization has a degausser in the basement. What media can it securely destroy? Each correct answer represents a complete solution. Choose two.

a)

Backup tapes

b)

Hard drives

c)

Optical discs

d)

Paper documents

e)

SSDs

35.

Among the options listed, which mitigation technique is known most for increasing security at the expense of flexibility?

a)

Application blacklisting

b)

Application whitelisting

c)

SOAR

d)

MDM

36.

A host on the network is potentially infected with a novel virus, and you don't want it to spread while you study it. You've decided that network segmentation won't be effective enough and you'd prefer to isolate the host. Which of the following will best achieve that goal?

a)

Changing firewall rules to exclude traffic to and from the affected host

b)

Changing the VLAN of the switch port to which the affected host connects

c)

Changing the IP address of the affected host

d)

Creating an air gap

37.

Which technology or category of products was developed to allow agents installed on hosts to report a variety of measurable statistics for central processing and analysis?

a)

NIDS

b)

UTM

c)

EDR

d)

HIDS

38.

Which of the following are essential security steps on all mobile devices?

Each correct answer represents a complete solution. Choose two.

a)

Using biometric authentication

b)

Configuring remote backup features

c)

Regularly applying operating system updates

d)

Configuring antivirus software

e)

Installing a firewall app

39.

It has come to your attention that a newly created sensitive document is making the rounds among authorized users in the company. Which enterprise utility can you adjust the configuration of to reduce the likelihood that the document will fall into the wrong hands in a readable format?

a)

MDM

b)

DLP

c)

SSL decryptor

d)

Firewall

40.

What is an example of IP theft?

a)

A competitor's use of the public IPv4 address space that was assigned by an ISP to your organization

b)

A competitor's unauthorized use of your organization's original engineering documents

c)

Publishing a textbook written by an independent author

d)

Downloading an operating system from the Ubuntu website and installing it without paying for it

41.

What kind of application centrally manages security policy and settings on all company mobile devices?

a)

GPS

b)

MAM

c)

MDM

d)

BYOD

42.

While analyzing the shortcomings in the operation of the enterprise's NIDS, you discover that in its current mode of operation, only known attacks are being reported. What is recommended to enable detection of previously unknown attack methods through the use of artificial intelligence (AI)?

a)

Heuristic

b)

Stateful protocol analysis

c)

Signature-based rule

d)

Passive detection

43.

Steffie wants to select a mobile device deployment method that provides employees with devices that are company-issued and supported, but employees can use them for personal reasons too. Which of the following is the most likely culprit?

a)

COBO

b)

COPE

c)

CYOD

d)

BYOD

44.

Which standard do you need to use when handling credit card data?

a)

NIST

b)

HIPAA

c)

PKI

d)

PCI DSS

45.

Which of the following is a proprietary wireless standard maintained by Silicon Labs and supports throughput up to 40 kbps over distances of 10-100m between nodes?

a)

Z-Wave

b)

Zigbee

c)

NB-IoT 

d)

CAN bus

46.

Which privacy-enhancing technology performs a reversible substitution of PII, storing the private data elsewhere, reducing the likelihood that a breach of the records containing the non-private substituted information will lead to legal jeopardy for the organization entrusted with the PII?

a)

Pseudo-anonymization

b)

Data minimization

c)

Full Anonymization

d)

Data masking

47.

Which privacy-enhancing technology neither alters original PII in a database nor creates a separate version in a new database and instead provides a representation of the sensitive data to the viewer in its original format, often replacing all parts of the sensitive information with the same character?

a)

Encryption

b)

Hashing

c)

Masking

d)

Tokenization

48.

Which of the following security risks is least important to address in enterprise patch management systems?

a)

Operating systems

b)

Applications

c)

CPU microcode

d)

Firmware

49.

Which of these statements about bash scripts is accurate?

a)

Bash scripts must be executed in a special command-line shell on top of the standard Linux shell.

b)

Bash scripts are more dangerous than PowerShell scripts because the attacker does not need elevated privileges to cause the same damage.

c)

Bash scripts are not dangerous until they are compiled into executables.

d)

Bash scripts can be used to attack Windows 10 machines. 

50.

Which of the following tools is used to sandbox suspected malware and report on what occurred during its execution?

a)

Nessus

b)

netstat

c)

cURL

d)

Cuckoo

51.

Which of the following statements is correct regarding BitLocker?

a)

Each user account has a separate BitLocker key stored in its settings.

b)

BitLocker-encrypted files are unreadable to other users on the same computer.

c)

Any user can independently encrypt files using BitLocker.

d)

It protects entire drives with personal and system files.

52.

You're classifying data for a private company which uses four classification levels. Under what classification does PHI most likely fall?

a)

Private

b)

Sensitive

c)

Confidential

d)

Critical

53.

Which authentication method allows a trusted system to vouch for the secure hardware and software configuration of another?

a)

Federation

b)

Remote attestation

c)

HOTP

d)

Directory services

54.

What data management model assists professionals in decision making with regard to the creation of policy based on the convergence of data security and privacy, focusing on such aspects as to how it's attained and classified, how it's used and stored, and how it's archived and destroyed?

a)

Privacy-enhancing technologies

b)

An impact assessment

c)

The information life cycle

d)

Public notifications and disclosures

55.

What kind of malware replicates itself by exploiting system vulnerabilities?

a)

Logic bomb

b)

Trojan horse

c)

Virus

d)

Worm

56.

You’ve taken up a contract helping to upgrade the existing industrial control network for an oil refinery. What network type should you expect to work with?

a)

SCADA

b)

IoT

c)

DCS

d)

VoIP

57.

Which mobile deployment model allows users to carry a single mobile device for business and personal use while allowing the enterprise to retain ownership of, and control over, the selection of devices on which support staff must be trained and skilled?

a)

COPE

b)

COBO

c)

BYOD

d)

CYOD

58.

Which of the following enterprise mobile deployment models introduces the greatest amount of risk for the implementing organization?

a)

COPE

b)

CYOD

c)

COBO

d)

BYOD

59.

Who among the following is a system administrator responsible for creating and enforcing the technical controls regarding access to data, under the direction of its owner?

a)

Privacy officer

b)

Data steward

c)

Data owner

d)

Data custodian

60.

What MDM features allow the administrator to silently update a corporate app and its content on mobile devices in the background?

Each correct answer represents a part of the solution. Choose two

a)

MAM

b)

Push notifications

c)

SMS/MMS

d)

VDI/VMI

e)

MCM 

61.

Which of the following delivers advertisements to the infected system, usually within a browser or other application windows?

a)

Virus

b)

Worm

c)

Adware

d)

Trojan

62.

You want to use your Android phone to store and manage cryptographic certificates. Which type of solution will you choose to do this using secure hardware?

a)

SEAndroid

b)

A microSD HSM

c)

MDM

d)

A wireless TPM

63.

You’ve traced some anomalous network activity infecting the whole department’s computers by stealing information. They're installed as add-ons with legitimate free software applications by popular download sites. What kind of malware is it?

a)

Botnet

b)

Trojan

c)

Spyware

d)

PUP

64.

A company configures workstations only to run software on an approved list. What is this an example of?

a)

Hardening

b)

Sandboxing

c)

Allow listing

d)

Block listing

65.

Question 79 :You’ve traced some anomalous network activity to malware that’s infected a whole department’s computers. The computers are processing a distributed task using spare CPU cycles, communicating with a remote server, and sending emails to random targets. What kind of malware is it?

a)

Botnet

b)

PUP

c)

Trojan

d)

Spyware

66.

Why might an administrator decide to employ an enterprise MDM solution to deny support for USB OTG on mobile devices?

a)

USB OTG can drain the mobile devices by allowing them to charge other devices.

b)

USB OTG supports the attachment of devices that block remote-wipe signals.

c)

Geolocation is unable to track devices running USB OTG.

d)

The connector on the mobile devices is used simultaneously for charging and for data transfer.

67.

What is the most common concern with regard to residential IoT devices and technologies?

a)

Weak default configurations

b)

Lack of standards

c)

No ability to encrypt transmissions

d)

Manufacturer lock-in

68.

Which of the following are differences between SED and non-SED FDE?

Each correct answer represents a complete solution. Choose two.

a)

SED drivers are supported by fewer operating systems.

b)

Opal is a standard that applies only to SED.

c)

SED-based encryption does not suffer from OS-related performance degradation.

d)

SED does not encrypt all data on the drive.

e)

SED does not require a key for encryption and decryption.

69.

Your organization has a degausser in the basement. What media can it securely destroy? Each correct answer represents a complete solution. Choose two.

a)

Backup tapes

b)

SSDs

c)

Paper documents

d)

Optical discs

e)

Hard drives

70.

What potential security risk does an SD card pose that a USB flash drive does not?

a)

Photographs of sensitive areas

b)

Wireless attacks

c)

Data exfiltration

d)

Malware