wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

ITP 126 - Pretest

Total questions: 69

Worksheet time: 1hrs 8mins

Name
Class
Date
1.
Although there are robust security measures due to the advancement of technology, threats and risk will still be able to penetrate computer security systems.
a)
True
b)
False
2.
The number of companies utilizing and shifting to cloud services is accelerating due to its security features.
a)
True
b)
False
3.
Point solutions are widely used to fix a problem or implement a new service quickly.
a)
True
b)
False
4.
An Integrated Threat Management (ITM) system is the same as a Unified/Universal Threat Management system.
a)
True
b)
False
5.
Point-Solution Architecture is more effective than Unified Architecture systems.
a)
True
b)
False
6.
Mobility in terms of security is less fundamental due to pandemic protocols forcing people to stay indoors.
a)
True
b)
False
7.
A threat is the potential for loss, damage, or destruction of assets or data caused by a risk.
a)
True
b)
False
8.
A risk is defined as some entity that may be capable of attacking or affecting the organization’s infrastructure.
a)
True
b)
False
9.
Identity and Access Management (IAM) services narrow the points of failure and backstop them with tools to catch mistakes when they're made.
a)
True
b)
False
10.
Through Identity and Access Management (IAM), employee access can be managed as a group of role instead of individually.
a)
True
b)
False
11.
Usernames and passwords are vulnerable to brute force attacks and can be stolen by third parties.
a)
True
b)
False
12.
Authentication involves the verification through different forms of identification.
a)
True
b)
False
13.
Access Management confirms that you are you and stores information about you.
a)
True
b)
False
14.
Identity Management uses the information about your identity to determine which software suites you're allowed access to and what you're allowed to do when you access them.
a)
True
b)
False
15.
Most modern Identity and Access Management (IAM) systems are managed by a server on the physical premises of an organization.
a)
True
b)
False
16.
Password manager applications are recommended in shared computers.
a)
True
b)
False
17.
A depth was when two messages were sent using the same wheel settings in a Lorenz Cipher.
a)
True
b)
False
18.
Under the principle of Coordinated Vulnerability Disclosure, researchers disclose newly discovered vulnerabilities in hardware, software, and services directly to the vendors of the affected product.
a)
True
b)
False
19.
It is possible to transmit a random secret key by sending a string of photons with the secret key encoded in their polarization.
a)
True
b)
False
20.
Digital computers and electronics helped in cryptanalysis, made possible to solve complex ciphers.
a)
True
b)
False
21.
The Lorenz Cipher was also called "Tummy" as dubbed by the Allies.
a)
True
b)
False
22.
The Vigenère cipher is probably the best-known example of a monoalphabetic cipher.
a)
True
b)
False
23.
Decryption is the process of converting plaintext into ciphertext.
a)
True
b)
False
24.
Cryptoanalysis is the combination of key, algorithm, and key management functions used to perform cryptographic
a)
True
b)
False
25.
Being "Defensible" is one of the benefits of ISMS. It is a structure that shows clear direction and authorization. Which of the following questions answer to the said benefit?
a)
Does the company have proper documentation for a third-party or international due diligence validation?
b)
Are your services marketed towards external information-sharing partners?
c)
Will the company have the ability to react and accept risk simultaneously?
d)
Does your company have board of directors that provides organizational vision and guiding principles in risk management?
26.
Being a "Differentiator" is one of the benefits of ISMS. It is when a degree of confidence towards partners are shared due to enhanced perception and image. Which of the following questions answer to the said benefit?
a)
Does the company have proper documentation for a third-party or international due diligence validation?
b)
Are your services marketed towards external information-sharing partners?
c)
Will the company have the ability to react and accept risk simultaneously?
d)
Does your company have board of directors that provides organizational vision and guiding principles in risk management?
27.
Being a "Business Enabler" is one of the benefits of ISMS. It is when the ISMS deploys control for regulations to meet collective requirements. Which of the following questions answer to the said benefit?
a)
Does the company have proper documentation for a third-party or international due diligence validation?
b)
Are your services marketed towards external information-sharing partners?
c)
Will the company have the ability to react and accept risk simultaneously?
d)
Does your company have board of directors that provides organizational vision and guiding principles in risk management?
28.
Having a "Structure" is one of the benefits of ISMS. It is when roles are delegated and understood within the organization and metrics are collected and analyzed for continuous process improvements. Which of the following questions answer to the said benefit?
a)
Does the company have proper documentation for a third-party or international due diligence validation?
b)
Are your services marketed towards external information-sharing partners?
c)
Will the company have the ability to react and accept risk simultaneously?
d)
Does your company have board of directors that provides organizational vision and guiding principles in risk management?
29.
Which is NOT a part of the building cycle of ISMS?
a)
Process
b)
Plan
c)
Do
d)
Check
e)
Act
30.
Which is NOT being assessed by an ISMS?
a)
Enterprise Risk
b)
Production Risk
c)
Program Risk
d)
Operational Risk
31.
"Knowledge" is one tool of Identity and Access Management (IAM) used in Multi-factor Authentication (ITM). Which of the following scenarios describe its use?
a)
Personal security questions are answered by an employee that forgot their password.
b)
A one-time password (OTP) is sent through email to verify online money transfer.
c)
A facial recognition is triggered in an iPhone X to allow automatic password fill up.
d)
User is logged off automatically due to suspicious activities based on the behavioral analysis check of a software.
32.
"Possession" is one tool of Identity and Access Management (IAM) used in Multi-factor Authentication (ITM). Which of the following scenarios describe its use?
a)
Personal security questions are answered by an employee that forgot their password.
b)
A one-time password (OTP) is sent through email to verify online money transfer.
c)
A facial recognition is triggered in an iPhone X to allow automatic password fill up.
d)
User is logged off automatically due to suspicious activities based on the behavioral analysis check of a software.
33.
"Inherence" is one tool of Identity and Access Management (IAM) used in Multi-factor Authentication (ITM). Which of the following scenarios describe its use?
a)
Personal security questions are answered by an employee that forgot their password.
b)
A one-time password (OTP) is sent through email to verify online money transfer.
c)
A facial recognition is triggered in an iPhone X to allow automatic password fill up.
d)
User is logged off automatically due to suspicious activities based on the behavioral analysis check of a software.
34.
"Adaptive Authentication" is one tool of Identity and Access Management (IAM) used in Multi-factor Authentication (ITM). Which of the following scenarios describe its use?
a)
Personal security questions are answered by an employee that forgot their password.
b)
A one-time password (OTP) is sent through email to verify online money transfer.
c)
A facial recognition is triggered in an iPhone X to allow automatic password fill up.
d)
User is logged off automatically due to suspicious activities based on the behavioral analysis check of a software.
35.
Which of the following is not a category of authentication?
a)
things you want
b)
things you know
c)
things you have
d)
things you are
36.
Which is not part of the four main types of authentication?
a)
Password-based authentication
b)
Multifactor-based authentication
c)
Certificate-based authentication
d)
eToken-based authentication
e)
Biometric-based authentication
37.
Cryptocurrency has no middlemen to charge transaction tolls. Which of the following scenarios are the possible "Implications for the Banked" due to the rise of cryptocurrency?
a)
Financial institutions are losing revenue due to fees being waived.
b)
People without financial security can access credit and are able to make international transfers.
c)
Users are able to verify the validity of a transaction on their own, without the assistance of banks.
d)
The economy is at risk of financial disorder due to the nonrecognition of authority.
38.
Large amounts of the unbanked live in developing nations where their capital is unprotected. Which of the following scenarios are the possible "Implications for the Unbanked" due to the rise of cryptocurrency?
a)
Financial institutions are losing revenue due to fees being waived.
b)
People without financial security can access credit and are able to make international transfers.
c)
Users are able to verify the validity of a transaction on their own, without the assistance of banks.
d)
The economy is at risk of financial disorder due to the nonrecognition of authority.
39.
Decentralized apps will be unable to monitor user activity, other than basic non-identifying metrics to keep their systems stable. Which of the following scenarios are the possible "Implications on E-Commerce" due to the rise of cryptocurrency?
a)
Financial institutions are losing revenue due to fees being waived.
b)
People without financial security can access credit and are able to make international transfers.
c)
Users are able to verify the validity of a transaction on their own, without the assistance of banks.
d)
The economy is at risk of financial disorder due to the nonrecognition of authority.
40.
No authority governs blockchains as they are run by netizens. Which of the following scenarios are the possible "Implications for Anarchists" due to the rise of cryptocurrency?
a)
Financial institutions are losing revenue due to fees being waived.
b)
People without financial security can access credit and are able to make international transfers.
c)
Users are able to verify the validity of a transaction on their own, without the assistance of banks.
d)
The economy is at risk of financial disorder due to the nonrecognition of authority.
41.
Which is NOT an application of Cryptography?
a)
Field relationships can be freely customized.
b)
Data is easily structured into categories.
c)
Data is consistent in input, meaning, and easy to navigate.
d)
Field relationships can be easily defined between data points.
42.
Which is NOT an advantage of a no-SQL database?
a)
Data is not confined to a structured group.
b)
Can easily use lookup functions to get data using primary keys.
c)
Can perform functions that allow for greater flexibility.
d)
Data and analysis can be more dynamic and allow for more variant inputs
43.
Which of the following core solution of an Integrated Threat Management (ITM) system?
a)
Integration of security modules to create a centralized prevention system.
b)
Auto-scaling with the cloud for up-to-date security measures.
c)
Security policy that expresses specific business needs.
d)
Managing different security environments such as cloud, mobile, and network.
44.
Why are Information Security Management Systems (ISMS) primarily created?
a)
To assign compliance and risk management via the INFOSEC Program.
b)
To standardize security operations as defined by Total Quality Management (TQM).
c)
To integrate people, processes, and technology to furnish enterprise information security services.
d)
To mitigate risk and threats within an organization.
45.
Which of the following best describes an ISMS?
a)
It is a combination of information security and a management system.
b)
It applies the management system conceptual model to the discipline of information security.
c)
It coordinates activities and best practices to direct and control information security and availability.
d)
It lives in multiple place and instances, based upon functional areas or information security domains.
46.
Which is the "best" practice to secure passwords?
a)
Creating passwords that include special symbols and numbers that is composed of eight or more characters.
b)
Not using real words nor personal data in the creation of passwords.
c)
Making patterns that are random and not sequential nor follows a specific format or order.
d)
Creating different passwords for different accounts and applications.
47.
Which is the main function of a password manager?
a)
To store important documents or other credentials like safe codes and medical information.
b)
To help users generate and store long and unique passwords for all online accounts.
c)
To help users know if their existing passwords are weak, reused, or have shown up in a data breach.
d)
To make users avoid being susceptible to identity theft and other crimes.
48.
Which of the following describes "authentication" best?
a)
It involves what you know, what you have, and who you are.
b)
It ensures that an entity is what it claims to be.
c)
It involves verification of entities through forms of identification.
d)
It is significant in Identity and Access Management (IAM).
49.
Which of the following qualifies cryptocurrency as a foundation of a modern "sound money" when compared to paper money?
a)
Cryptocurrency is designed to be scarce and durable due to mathematical algorithms.
b)
Cryptocurrency is freely transferrable and can be subdivided into smaller units.
c)
Cryptocurrency can be substituted globally making it soundly fungible.
d)
Cryptocurrency is easily recognizable due to its framework and structure.
50.
Which of the following makes the "blockchain" most secure?
a)
A number only used once or "nonce" is used and encrypted and rehashed.
b)
PoW mining process lets miners solve a mathematical puzzle in order to discover the next block hash.
c)
Merkle root is used to ensure that data blocks sent through a peer-to-peer network are unaltered.
d)
Timestamp is updated roughly every 10 minutes to ensure latest information are uploaded.
51.

Decrypt the ciphertext CARHZBABHYGENZVPEBFPBCVPFVYVPBIBYPNABPBAVBFVF into plaintext using Caesar Cipher method. Shift 13.

(a)  

52.

What is the shifting value if the ciphertext is 'PVAPPVAB' and plaintext is 'CINCCINO'.

(a)  

53.
Many individuals and organizations are at risk of becoming cyber victims on a daily basis.
a)
True
b)
False
54.
Security refers to the policies, procedures, and technical measures used to prevent unauthorized access, alteration, theft, or physical damage to information systems.
a)
True
b)
False
55.
Employees can also become threats to organizational data.
a)
True
b)
False
56.
Social engineering involves intruders tricking employees to gain system access.
a)
True
b)
False
57.
Access denial is the unauthorized or unwanted entry into a private computer and/or network services.
a)
True
b)
False
58.
Access acquisition is the prevention of entry to a computer and/or network services.
a)
True
b)
False
59.
Wardiving can be performed when the intruder is far away from the target victim location.
a)
True
b)
False
60.
Local area networks (LAN) using the 802.11 standard has robust security and is impenetrable.
a)
True
b)
False
61.
A computer virus is a rogue software program that attaches itself to other software programs or data files to be executed, usually without user knowledge or permission. Which is an example of this malware?
a)
A malware that automatically creates a shortcut whenever a flash drive is inserted into the PC
b)
The ILOVEYOU malware that spread like wildfire in 2000 and did more than $15 billion in damage.
c)
The CryptoLocker encrypts files and demands money from users in exchange for the decryption key.
d)
The CoolWebSearch hijacked the internet explorer, changed the setting, and sent browsing data to the programmer.
62.
Worms are independent computer programs that copy themselves from one computer to other computers over a network. Which is an example of this malware?
a)
A malware that automatically creates a shortcut whenever a flash drive is inserted into the PC
b)
The ILOVEYOU malware that spread like wildfire in 2000 and did more than $15 billion in damage.
c)
The CryptoLocker encrypts files and demands money from users in exchange for the decryption key.
d)
The CoolWebSearch hijacked the internet explorer, changed the setting, and sent browsing data to the programmer.
63.
Ransomware tries to extort money from users by taking control of their computers or displaying annoying pop-up messages. Which is an example of this malware?
a)
A malware that automatically creates a shortcut whenever a flash drive is inserted into the PC
b)
The ILOVEYOU malware that spread like wildfire in 2000 and did more than $15 billion in damage.
c)
The CryptoLocker encrypts files and demands money from users in exchange for the decryption key.
d)
The CoolWebSearch hijacked the internet explorer, changed the setting, and sent browsing data to the programmer.
64.
Spyware are small programs install themselves surreptitiously on computers to monitor user web-surfing activity and serve up advertising. Which is an example of this malware?
a)
A malware that automatically creates a shortcut whenever a flash drive is inserted into the PC
b)
The ILOVEYOU malware that spread like wildfire in 2000 and did more than $15 billion in damage.
c)
The CryptoLocker encrypts files and demands money from users in exchange for the decryption key.
d)
The CoolWebSearch hijacked the internet explorer, changed the setting, and sent browsing data to the programmer.
65.
Which of the following is NOT a medium for internet vulnerabilities?
a)
Desktop Software Application
b)
Voice over IP (VoIP)
c)
Email or Instant Messaging
d)
Peer-to-Peer (P2P) file-sharing programs
66.
Which of the following is NOT a reason why employees are also considered threats to the company?
a)
Employees have access to privileged information.
b)
Employees are being background checked by the company before they are employed.
c)
Employees’ lack of knowledge or awareness towards network security breaches.
d)
Employees may allow other users to use their account passwords for authentication.
67.
Which of the following safety measures best stresses out the importance of using a strong password system?
a)
Bolster Access Control
b)
Keep All Software Updated
c)
Scan for Malware
d)
Standardize Software
68.
Which of the four key hazards is initiated by a malware?
a)
Data theft from government computers, such as military secrets.
b)
Vandalism, such as a computer virus destroying data.
c)
Fraud, such as bank personnel routing funds into their own accounts.
d)
Invasion of privacy, such as unauthorized access to protected personal financial or medical data from a huge database.
69.
Which of the cybercrime acts is the most prominent in our country?
a)
Unauthorized data disclosure
b)
Cyber libel
c)
Cyberbullying
d)
All of the above.