NEW
Font size
WorksheetsPractice Test for Information Assurance and Security 1 - Prelims
Total questions: 70
Worksheet time: 35mins
It is an asset that, like other important business assets, has value to an organization and consequently needs to be suitably protected.
Security
Information Security
Information
Information System
The architecture where an integrated combination of appliances, systems and solutions, software, alarms, and vulnerability scans working together
Information
Information System
Security
Information Security
Which of the following is NOT an Information Security statement?
Networks that computers and devices use should also be secured
Computers and digital devices are becoming integral to conducting business
Which also makes them a target of attack
Devices needs to be secured
It restricts access to authorized individuals.
Availability
Integrity
Confidentiality
Authentication
The information can be accessed and modified by authorized individuals in an appropriate timeframe.
Authentication
Integrity
Availability
Confidentiality
It is a factor of identification that has a user ID and password.
Something you know
Something you are
Something you have
Something you keep
It is a factor of identification that uses physical characteristics.
Something you are
Something you keep
Something you have
Something you know
It only provides access to information necessary to perform their job duties to read, modify, add, and/or delete information.
Password
Access Control
Virtual Private Networks
Authentication
It is created for each resource that can read, write, delete or add information.
Access Control
Access control list
Authentication
Role-based access control
It is an algorithm that encodes or scrambles information during transmission or storage.
symmetric key
asymmetric key
decryption
encryption
It is a possibility that a threat exploits a vulnerability in an asset and causes damage or loss to the asset.
Risk
Vulnerability
Threat
Agent
It is something that can potentially cause damage to the organization, IT Systems or network.
Risk
Agent
Threat
Vulnerability
It is a weakness in the organization, IT Systems, or network that can be exploited by a threat.
Risk
Agent
Vulnerability
Threat
Which is NOT an Element of Threats?
Agent
Motive
Risk
Result
Which of the following is NOT an Agent of threat element?
Human
Machine
Software
Nature
It is an element of threat that outcomes the applied threat.
Agent
Motive
Result
Risk
Which of the following is NOT a possible threat?
External Parties
Employees
Growth in networking and distributed computing
High awareness of security issues
Which of the following is NOT a Threat Source?
Terroist
Internal Hackers
Owner of the company
Poorly trained employees
To provide management direction and support for Information security.
Human Resources Security
Asset Management
Information Security Policy
Organization of Information Security
To prevent unauthorized access, theft, compromise, damage information and information processing facilities.
Physical & Environmental Security
Information Systems Acquisition
Access Control
Communications & Operations Management
It is manipulating a person into knowingly or unknowingly giving up information.
Risk Mangement
Threats
Social Engineering
Information Security
Which of the following is NOT part of the Social Engineering attack cycle?
execution
exploitation/expedition
information gathering
developing relationship
It is an aggressor that will first try to build up a good bonding with the target and he makes sure that he gains the trust of the target which he’ll later exploit.
Developing Relationship
Information Gathering
Execution
Exploitation
Once the target has finished the task requested by the attacker,
the cycle is complete.
Exploitation
Developing Relationship
Execution
Information Gathering
These attacks deceive the user into
believing that the application in use is truly providing them with
security which is not the fact always.
Tactical attacks
Phishing
Technical attacks
Non-technical attacks
Which of the following is NOT part of the Pre-atack Phase?
Enumeration
Identification
Scanning
Footprinting
Which of the following is NOT Information Gathering Methodology?
Ignore operating systems
Locate the network range
Unearth initial information
Ascertain active machines
It is used to find personal information like residential addresses, contact numbers, date of birth, and change of location.
Web Data Extractor
People Search
DNS Enumerator
SpiderFoot
It is a free, open-source, domain footprinting tool that will scarpe the websites on the domain, as well as search Google, Netcraft, DNS to build up information.
People Search
Web Data Extractor
DNS Enumerator
SpiderFoot
It is a tool to extract targeted company's contact data from the internet.
People Search
SpiderFoot
Web Data Extractor
DNS Enumerator
It integrates the world's most advanced route tracing software with performance measurements.
Path Analyzer Pro
Google Earth
Reamweaver
eMailTrackerPro
It uses planet imagery and geographic information right on your desktop.
Reamweaver
eMailTrackerPro
Path Analyzer Pro
Google Earth
It is an email analysis tool that enables analysis of an email and its headers automatically and provides graphical results.
Path Analyzer Pro
Google Earth
Reamweaver
eMailTrackerPro
It is a web site stealing tool that has everything you need instantly.
eMailTrackerPro
Reamweaver
Google Earth
Path Analyzer Pro
It is an automated sub-domain retrieval tool.
DNS Enumerator
SpiderFoot
People Search
Web Data Extractor
It provides rich information to perform passive reconnaissance.
Web Data Extractor
DNS Enumerator
People Search
It is the process of gathering resources regarding a target computer or network system.
Footprinting
Scanning
Identification
Enumeration
Which of the following is not a Footprinting resource?
temperature today
phone number
IP addresses
e-mail addresses
It is used to query information regarding certain domain names.
who.is
nslookup
SmartWhois
tracert
It is a tool that connects to an available database to provide information regarding a domain or host.
SmartWhois
tracert
who.is
nslookup
It is a program that provides the hostname of a particular IP address and vice-versa.
NsLookup
Whois
SmartWhois
tracert
It is a program that traces packet routes.
tracert
SmartWhois
nslookup
who.is
It is is a graphical version of tracert.
SmartWhois
Neo trace and visual route
tracert
Sam Spade
It is a general purpose Internet utility package which includes ping, nslookup, whois, IP block, and traceroute function.
tracert
Sam Spade
Neo trace and visual route
SmartWhois
It detects the live system on target network and services running on target computer.
Pinger
War Dialers
Scanning
Port scanner
These are tools that is used to scan a range of phone nos. for vulnerable modems.
War Dialers
Pinger
Scanning
Port scanner
It is a tool that sends an ICMP echo request to a range of IP addresses and lists all hosts that reply.
War Dialers
Pinger
Scanning
Port Scanner
It is a tool that is used to detect services running in a computer.
Port scanner
Scanning
War Dialers
Pinger
It is used to determine the operating system running in a computer.
Foot printing
Hand printing
Port scanner
Finger printing
It is a type of Fingerprinting that takes advantage of the fact that OS vendors implement the TCP stack differently and sends a packet to target computer and based on the response it guesses the OS running in the computer.
Foot printing active
Finger printing passive
Finger printing active
Foot printing passive
It is recognized as essential to protect vital processes and the systems that provide those processes.
Security
Information
Information Security
Policy
It is a management framework for implementation.
Organization of Information Security
Information Security Policy
Asset Mangement
Human Resources Security
To ensure the security of valuable organizational IT and its related assets.
Organization of Information Security
Asset Management
Human Resources Security
Information Security Policy
To reduce the risks of human error, theft, fraud or misuse of facilities.
Asset Mangement
Information Security Policy
Organization of Information Security
Human Resources Security
The target could then be manipulated by the ‘trusted’ attacker to reveal their sensitive information like password to carry out an action.
Exploitation
Information Gathering
Developing Relationship
Execution
There could be variety of techniques which is used by the aggressor to gather sensitive information about the target(s).
Exploitation
Developing Relationship
Information Gathering
Execution
It can be made private using an internal network to limit access to them.
Virtual Private Network (VPN)
Firewalls
Access Control
Authentication
Single-factor authentication (user ID/password) is the easiest to break.
Backup
Encryption
Password
Firewalls
Persons accessing the information is who they say they are.
Authentication
Access Control
Firewalls
Backup
Data has not been altered in an unauthorized manner.
Integrity
Availability
Confidentiality
Result
These attacks are those attacks that are purely perpetrated through
the art of deception.
Non-technical attacks
Technical attacks
Attack
Social Engineering attacks
It is a new term of the century which is used to take over a private.
Support Staff
Spam e-mails
Phishing
Hoaxing
Hundreds and thousands of e-mails are
sent to the victim. This is tightly related with phishing attempt.
Hoaxing
Spam e-mails
Phishing
Support Staff
The attacker acts as a clean support crew to help users to fix any problem
Support Staff
Hoaxing
Spam e-mails
Phishing
It is a trick to make the user believe that something false is real.
Spam e-mails
Hoaxing
Support Staff
Phishing
The attacker can call up to the organization’s computer help desk and pretend to have trouble accessing the system.
Authoritative Voice
Hoaxing
Support Staff
Spam e-mails
It is an element of threat performs as a catalyst of threat.
Information
Motive
Result
Agent
It is an element of threat that causes the agent to act.
Result
Motive
Agent
Security
To ensure the correct and secure operation of information processing facilities.
Communications & Operations Management
Access Control
Information Security Incident Management
Information Systems Acquisition, Development & Maintenance
To ensure security built into information systems.
Communications & Operations Management
Information Systems Acquisition, Development & Maintenance
Access Control
Information Security Incident Management
