Font size
Worksheets#01.01 Foundations of Cybersecurity Module 1
Total questions: 24
Worksheet time: 14mins
Fill in the blank: The purpose of _____ is to protect networks, devices, people, and data from unauthorized access or criminal exploitation.
change-management
business continuity
cybersecurity
planning
Fill in the blank: Cybersecurity aims to protect networks, devices, people, and data from _____ or unauthorized access.
poor financial management
market shifts
criminal exploitation
changing business priorities
Fill in the blank: Cybersecurity aims to protect networks, devices, people, and data from _____ or criminal exploitation.
unauthorized access
changing business priorities
poor financial management
market shifts
What occurs during a security audit?
Review of an organization’s security records, activities, and other related documents
Ethical hacking of an organization's internal network to identify vulnerabilities
Analyzing the efficiency of an organization's internal network
Prioritizing tasks, processes, and procedures
Which of the following tasks are typically responsibilities of entry-level security analysts? Select all that apply.
Protecting computer and network systems
Examining in-house security issues
Installing prevention software
Creating organizational policies
Which of the following entities may be an internal threat to an organization? Select three answers.
Vendors
Trusted partners
Employees
Customers
Someone outside of an organization attempts to gain access to its private information. What type of threat does this scenario describe?
External
Accidental
Ethical
Internal
An employee receives an email that they believe to be legitimate. They click on a compromised link within the email. What type of internal threat does this scenario describe?
Abusive
Operational
Accidental
Intentional
What is identity theft?
Stealing personal information to commit fraud while impersonating a victim
A data breach that affects an entire organization
Failing to maintain and secure user, customer, and vendor data
Trying to gain access to an organization’s private networks
Fill in the blank: Identity theft is the act of stealing _____ to commit fraud while impersonating a victim.
hardware
personal information
business records
trade secrets
An individual has their personal information stolen. They discover that someone is using that information to impersonate them and commit fraud. What does this scenario describe?
Identity theft
Network infiltration
Secured customer data
Data breach
What are some key benefits associated with an organization meeting regulatory compliance? Select two answers.
Upholding ethical obligations
Identifying trends
Recruiting employees
Avoiding fines
What is regulatory compliance?
Threats and risks from employees and external vendors
Laws and guidelines that require implementation of security standards
Expenses and fines associated with vulnerabilities
Sites and services that require complex passwords to access
Fill in the blank: An organization that is in regulatory compliance is likely to _____ fines.
incur
encounter
avoid
rectify
An individual is in their first job as an entry-level security professional. They apply the problem-solving proficiencies that they learned in past roles to their current security career. What does this scenario describe?
Taking on-the-job training
Understanding business standards
Having expertise with a specific procedure
Using transferable skills
An individual is in their first job as an entry-level security professional. They take training to learn more about the specific tools, procedures, and policies that are involved in their career. What does this scenario describe?
Gaining new technical skills
Improving management capabilities
Transferring capabilities from one career to another
Understanding different perspectives
Which of the following proficiencies are examples of technical skills? Select two answers.
Applying computer forensics
Automating tasks with programming
Communicating with employees
Prioritizing collaboration
Fill in the blank: Security information and event _____ (SIEM) tools enable security professionals to identify and analyze threats, risks, and vulnerabilities.
monitoring
management
maturity
mitigation
Fill in the blank: Security information and _____ management (SIEM) tools enable security professionals to identify and analyze threats, risks, and vulnerabilities.
employer
emergency
enterprise
event
Fill in the blank: Security _____ and event management (SIEM) tools enable security professionals to identify and analyze threats, risks, and vulnerabilities.
intelligence
information
identity
improvement
A security professional receives an alert about an unknown user accessing a system within their organization. They attempt to identify, analyze, and preserve the associated criminal evidence. What security task does this scenario describe?
Programming with code
Computer forensics
Software upgrades
Resolving error messages
A security professional investigates an alert about an unknown user accessing a system within their organization. What is the purpose of computer forensics in this situation?
Implement tools that help detect an incident
Establish new security frameworks, controls, and regulations for the business
Identify, analyze, and preserve criminal evidence
Make upgrades to network security
Which of the following statements accurately describe personally identifiable information (PII) and sensitive personally identifiable information (SPII)? Select all that apply.
An example of SPII is someone’s financial information.
The theft of PII is often more damaging than the theft of SPII.
An example of PII is someone’s date of birth.
Both PII and SPII are vulnerable to identity theft.
Which of the following statements accurately describe personally identifiable information (PII) and sensitive personally identifiable information (SPII)? Select all that apply.
An example of PII is someone’s phone number.
An example of SPII is someone’s biometric data.
Only SPII is vulnerable to identity theft.
PII is any information used to infer an individual’s identity.
