WorksheetsCybersecurity Final 2022-2023 Bedford
Total questions: 35
Worksheet time: 18mins
True or False: Physical security is the protection of corporate assets from threats such as unauthorized entry, theft or damage.
True
False
True or False: Prevention is taking the steps necessary to avert unauthorized access, theft, damage, or other type of security breach.
True
False
True or False: Detection is identifying that a security breach has happened or is happening.
True
False
True or False: FalseRecovery is the process of returning a system to a functional state and repairing any damage.
True
False
True or False: Access list is a list of personnel who are unauthorized to enter a secure facility
True
False
True or False: Mantrap is a specialized Defense with two locking doors that create a security buffer zone between two areas.
True
False
True or False: Turnstile is a vapor that permits entry in only one direction.
True
False
True or False: Double-entry door is a double-entry door has two doors that are locked from the outside but have crash bars on the inside that allow easy exit.
True
False
True or False: Bollards are short, sturdy posts used to prevent a vehicle from crashing into a secure area.
True
False
True or False: Smart cards are access cards that have encrypted access information.
True
False
True or False: Smart cards can be contactless or require contact.
True
False
True or False: Proximity cards, also known as radio frequency identification (RFID) cards, are a subset of smart cards that use the 125 kHz frequency to communicate with proximity readers.
True
False
True or False: Biometric locks increase security by using fingerprints or iris scans. They reduce the threat from lost keys or cards.
True
False
Pretending to be somebody else and approaching a target to extract information is called what?
Preloading
Footprinting
Impersonation
Pretexting
Which of the following is the BEST example of the principle of least privilege?
Jill has been given access to all of the files on one server.
Mary has been given access to all of the file servers.
Wanda has been given access to the files that she needs for her job.
Lenny has been given access to files that he does not need for his job.
Which of the following BEST describes an inside attacker?
An agent who uses their technical knowledge to bypass security.
A good guy who tries to help a company see their vulnerabilities.
An attacker with lots of resources and money at their disposal.
An unintentional threat actor. This is the most common threat.
DNS tunneling is a common method that allows an attacker to accomplish which attack?
Data loss
Availability loss
Medical identity theft
Data exfiltration
Which security control, if not applied, can allow an attacker to bypass other security controls?
Principle of least privilege
Updating firmware or software
Physical access control
Changing default passwords
What is the BEST defense against script kiddie attacks?
Build a comprehensive security approach that uses all aspects of threat prevention and protection.
Properly secure and store data backups.
Have appropriate physical security controls in place.
Keep systems up to date and use standard security practices.
Sometimes, an attacker's goal is to prevent access to a system rather than to gain access. This form of attack is often called a denial-of-service attack and causes which impact?
Availability loss
Identity theft
Data loss
Data exfiltration
Which deviation in power is the longest in duration?
Surge
Transient
Blackout
Sag
Burning, pulping, and shredding are three ways to securely dispose of data in which form?
Disk
Tape
Cloud
Paper
Which special network area is used to provide added protection by isolating publicly accessible servers?
VLAN
Internet
Intranet
DMZ
What is the recommended humidity level for server rooms?
10% or lower
30%
50%
Under 50%
Which of the following can be used to stop piggybacking at a front entrance where employees should swipe smart cards to gain entry?
Use key locks rather than electronic locks
Deploy a mantrap
Install security cameras
Use weight scales
Documenting procedures and processes are part of which milestone in the NSA's Manageable Network Plan?
Control Your Network
Prepare to Document
Document Your Network
Reach Your Network
What does the "netstat -a" command show?
What does the netstat -a command show?
All listening and non-listening sockets
All listening sockets
All connected hosts
Which of the following technologies is used to provide secure remote access to internal network resources?
Intrusion Detection System (IDS)
Virtual Local Area Network (VLAN)
Virtual Private Network (VPN)
Public Key Infrastructure (PKI)
Which of the following is a common security measure implemented in wireless networks to protect against unauthorized access?
Firewall
Intrusion Detection System (IDS)
MAC filtering
Patch management
Which of the following authentication methods uses a physical characteristic of an individual to verify their identity?
Password authentication
Two-factor authentication (2FA)
Biometric authentication
Token-based authentication
Which of the following is an essential principle of least privilege (POLP)?
Assigning users the maximum privileges by default
Allowing users to choose their own access permissions
Granting permissions based on job roles and responsibilities
Giving unrestricted access to all network resources
Which of the following encryption algorithms is considered asymmetric or public key cryptography?
Advanced Encryption Standard (AES)
Data Encryption Standard (DES)
Rivest-Shamir-Adleman (RSA)
Triple Data Encryption Algorithm (3DEA)
Which of the following is a function of a certificate authority (CA) in a PKI?
Encrypting data using a public key
Generating digital signatures for documents
Managing the revocation of digital certificates
Encrypting and decrypting symmetric keys
Which of the following is an example of a hashing algorithm commonly used for password storage?
AES
RSA
SHA-256
Diffie-Hellman
Which of the following is a characteristic of a digital signature?
It provides confidentiality of the data.
It ensures integrity and non-repudiation.
It encrypts data using a symmetric key.
It is generated by a certificate authority (CA).
