wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Cybersecurity Final 2022-2023 Bedford

Total questions: 35

Worksheet time: 18mins

Name
Class
Date
1.

True or False: Physical security is the protection of corporate assets from threats such as unauthorized entry, theft or damage.

a)

True

b)

False

2.

True or False: Prevention is taking the steps necessary to avert unauthorized access, theft, damage, or other type of security breach.

a)

True

b)

False

3.

True or False: Detection is identifying that a security breach has happened or is happening.

a)

True

b)

False

4.

True or False:  FalseRecovery is the process of returning a system to a functional state and repairing any damage.

a)

True

b)

False

5.

True or False: Access list is a list of personnel who are unauthorized to enter a secure facility

a)

True

b)

False

6.

True or False: Mantrap is a specialized Defense  with two locking doors that create a security buffer zone between two areas.

a)

True

b)

False

7.

True or False: Turnstile is a vapor that permits entry in only one direction.

a)

True

b)

False

8.

True or False: Double-entry door is a double-entry door has two doors that are locked from the outside but have crash bars on the inside that allow easy exit.

a)

True

b)

False

9.

True or False: Bollards are short, sturdy posts used to prevent a vehicle from crashing into a secure area.

a)

True

b)

False

10.

True or False: Smart cards are access cards that have encrypted access information.

a)

True

b)

False

11.

True or False: Smart cards can be contactless or require contact.

a)

True

b)

False

12.

True or False: Proximity cards, also known as radio frequency identification (RFID) cards, are a subset of smart cards that use the 125 kHz frequency to communicate with proximity readers.

a)

True

b)

False

13.

True or False: Biometric locks increase security by using fingerprints or iris scans. They reduce the threat from lost keys or cards.

a)

True

b)

False

14.

Pretending to be somebody else and approaching a target to extract information is called what?

a)

Preloading

b)

Footprinting

c)

Impersonation

d)

Pretexting

15.

Which of the following is the BEST example of the principle of least privilege?

a)

Jill has been given access to all of the files on one server.

b)

Mary has been given access to all of the file servers.

c)

Wanda has been given access to the files that she needs for her job.

d)

Lenny has been given access to files that he does not need for his job.

16.

Which of the following BEST describes an inside attacker?

a)

An agent who uses their technical knowledge to bypass security.

b)

A good guy who tries to help a company see their vulnerabilities.

c)

An attacker with lots of resources and money at their disposal.

d)

An unintentional threat actor. This is the most common threat.

17.

DNS tunneling is a common method that allows an attacker to accomplish which attack?

a)

Data loss

b)

Availability loss

c)

Medical identity theft

d)

Data exfiltration

18.

Which security control, if not applied, can allow an attacker to bypass other security controls?

a)

Principle of least privilege

b)

Updating firmware or software

c)

Physical access control

d)

Changing default passwords

19.

What is the BEST defense against script kiddie attacks?

a)

Build a comprehensive security approach that uses all aspects of threat prevention and protection.

b)

Properly secure and store data backups.

c)

Have appropriate physical security controls in place.

d)

Keep systems up to date and use standard security practices.

20.

Sometimes, an attacker's goal is to prevent access to a system rather than to gain access. This form of attack is often called a denial-of-service attack and causes which impact?

a)

Availability loss

b)

Identity theft

c)

Data loss

d)

Data exfiltration

21.

Which deviation in power is the longest in duration?

a)

Surge

b)

Transient

c)

Blackout

d)

Sag

22.

Burning, pulping, and shredding are three ways to securely dispose of data in which form?

a)

Disk

b)

Tape

c)

Cloud

d)

Paper

23.

Which special network area is used to provide added protection by isolating publicly accessible servers?

a)

VLAN

b)

Internet

c)

Intranet

d)

DMZ

24.

What is the recommended humidity level for server rooms?

a)

10% or lower

b)

30%

c)

50%

d)

Under 50%

25.

Which of the following can be used to stop piggybacking at a front entrance where employees should swipe smart cards to gain entry?

a)

Use key locks rather than electronic locks

b)

Deploy a mantrap

c)

Install security cameras

d)

Use weight scales

26.

Documenting procedures and processes are part of which milestone in the NSA's Manageable Network Plan?

a)

Control Your Network

b)

Prepare to Document

c)

Document Your Network

d)

Reach Your Network

27.

What does the "netstat -a" command show?

a)

What does the netstat -a command show?

b)

All listening and non-listening sockets

c)

All listening sockets

d)

All connected hosts

28.

Which of the following technologies is used to provide secure remote access to internal network resources?

a)

Intrusion Detection System (IDS)

b)

Virtual Local Area Network (VLAN)

c)

Virtual Private Network (VPN)

d)

Public Key Infrastructure (PKI)

29.

Which of the following is a common security measure implemented in wireless networks to protect against unauthorized access?

a)

Firewall

b)

Intrusion Detection System (IDS)

c)

MAC filtering

d)

Patch management

30.

Which of the following authentication methods uses a physical characteristic of an individual to verify their identity?

a)

Password authentication

b)

Two-factor authentication (2FA)

c)

 Biometric authentication

d)

Token-based authentication

31.

Which of the following is an essential principle of least privilege (POLP)?

a)

Assigning users the maximum privileges by default

b)

Allowing users to choose their own access permissions

c)

Granting permissions based on job roles and responsibilities

d)

Giving unrestricted access to all network resources

32.

Which of the following encryption algorithms is considered asymmetric or public key cryptography?

a)

Advanced Encryption Standard (AES)

b)

Data Encryption Standard (DES)

c)

Rivest-Shamir-Adleman (RSA)

d)

Triple Data Encryption Algorithm (3DEA)

33.

Which of the following is a function of a certificate authority (CA) in a PKI?

a)

Encrypting data using a public key

b)

Generating digital signatures for documents

c)

Managing the revocation of digital certificates

d)

Encrypting and decrypting symmetric keys

34.

Which of the following is an example of a hashing algorithm commonly used for password storage?

a)

AES

b)

RSA

c)

SHA-256

d)

Diffie-Hellman

35.

Which of the following is a characteristic of a digital signature?

a)

It provides confidentiality of the data.

b)

It ensures integrity and non-repudiation.

c)

It encrypts data using a symmetric key.

d)

It is generated by a certificate authority (CA).