WorksheetsICITP Certification Quiz
Total questions: 100
Worksheet time: 1hrs 8mins
What is a common method used by cybercriminals to trick individuals into providing sensitive information such as passwords or credit card details?
Spoofing
Malware
Shoulder surfing
Phishing
Which component acts as a barrier between a trusted internal network and untrusted external networks in order to control incoming and outgoing network traffic?
Router
Switch
Firewall
Antivirus
What process converts sensitive information into a secret code to protect it during transmission or storage?
Obfuscation
Decryption
Encoding
Encryption
What type of software is designed to infiltrate or damage a computer system without the owner's consent?
Spyware
Trojan
Malware
Ransomware
How can individuals protect themselves from social engineering attacks that manipulate human behavior to divulge confidential information?
Ignore any security warnings
Be cautious of unsolicited requests, verify identities, avoid suspicious links, update passwords regularly.
Share passwords with strangers
Click on all links in emails
What is the term used to describe a type of cyber attack where the attacker pretends to be someone else in order to steal sensitive information?
Impersonation
Eavesdropping
Denial of Service
Packet Sniffing
Which of the following is a common method used by cybercriminals to gain unauthorized access to a system by guessing passwords?
Brute Force Attack
Phishing Attack
SQL Injection
Man-in-the-Middle Attack
What security measure involves verifying the identity of a user by requiring two or more pieces of evidence?
Single Sign-On
Multi-Factor Authentication
Biometric Authentication
Single-Factor Authentication
Map Identification and Authentication with the corresponding attribute of CIA
Confidentiality
Integrity
Availability
What is a keylogger
Virus
Spyware
Adware
Windows Analysis tool
Special types of viruses that can travel from computer to computer without human action; self-replicating and can multiply until it uses up the computer's resources
Spyware
Worms
Trojans
Phishing
Asymmetric encryption uses only 1 key.
True
False
Maybe
God Knows
The process of converting a ciphertext into plaintext.
encryption
decryption
plaintext
cryptography
In public key cryptography, what is the private key used for?
Encrypting data
Decrypting data
Verifying digital signatures
Generating digital signatures
What does SSL stand for?
Secure Socket Layer
Secret Secure Layer
In the realm of cybersecurity, how is the term "vulnerability" defined?
An impenetrable system
A system flaw susceptible to exploitation
An encryption standard
A network communication protocol
What does availability of data refer to?
The level of assurance that data exists
The level of assurance that data will be restricted to people who need it, when they need it
The level of assurance that data will be accurate and trustworthy
The level of assurance that data will be available to people who need it, when they need it
What does integrity of data refer to?
The level of assurance which can be given as to how structured data is
The level of assurance which can be given as to how accurate and trustworthy data is
The level of assurance which can be given as to how strong data is
The level of assurance which can be given as to how relevant the data is
Emma is working at a bank and discovers that she is able to transfer $10,000 to her account from a customer's account without any authorization.
Which part of the CIA triad has been broken?
C
I
A
None of the above
What does integrity of data refer to?
The level of assurance which can be given as to how structured data is
The level of assurance which can be given as to how accurate and trustworthy data is
The level of assurance which can be given as to how strong data is
The level of assurance which can be given as to how relevant the data is
What does availability of data refer to?
The level of assurance that data exists
The level of assurance that data will be restricted to people who need it, when they need it
The level of assurance that data will be accurate and trustworthy
The level of assurance that data will be available to people who need it, when they need it
What is the principle of "Least Privilege" in cybersecurity?
Changing passwords frequently
Anika opens her fitness tracking app to start logging a workout. The app crashes, and she is unable to log her workout.
C
I
A
None of the above
Ensuring the safety of the school premises, conducting regular fire drills, installing security cameras, providing emergency response training, and having a well-defined evacuation plan are methods to ensure
Protection
Integrity
Confidentiality
Availability
What is the process of verifying a person's identity?
Authentication
Authorization
Auditing
Accounting
In the realm of cybersecurity, how is the term "vulnerability" defined?
An impenetrable system
A system flaw susceptible to exploitation
An encryption standard
A network communication protocol
What does GUI stand for in the context of computer technology?
General Utilities Intervention
Graphical User Interface
General User Intervention
Graphical Utilities Interface
Which best describes a "botnet"?
A malware persistence mechanism
ChatGPT
A collection of automated scripts used for system compromise
A collection of infected computers controlled by a hacker
"WannaCry" is a type of what?
exploit
worm
ransomware
trojan
Which type of malware disguises itself as a legitimate software update to trick users into downloading and executing it?
Virus
Worm
Trojan
Ransomware
What cybersecurity principle involves protecting sensitive information from unauthorized access or disclosure?
Availability
Integrity
Confidentiality
Authentication
Olivia suspects that her computer has been infected with malware. Which type of malware collects user data, including keystrokes and browsing habits, without their knowledge?
Adware
Spyware
Ransomware
Worm
Which cybersecurity concept focuses on ensuring that critical systems are available and accessible when needed during a cyber attack?
Integrity
Confidentiality
Availability
Authorization
Enumerate the various categories of hackers in the context of a cybersecurity workshop.
Insider Threat, Phishing, Ransomware, Firewall
Malware, Spyware, Adware, Worm
Black Hat, White Hat, Blue Hat, Red Hat
White Hat, Black Hat, Grey Hat.
The presence of a weakness in a system, program, or network is referred to as a:
vulnerability
exploit
adware
malware
John finds a message on his phone that he thinks might be a scam. He should:
Forward the message to his friends to see if they think it's a scam too.
Reply and ask the sender not to send more mail.
Delete the message
Change your phone number
What purpose does a hypervisor serve in the context of virtualization?
Ensuring secure network traffic
Facilitating the creation of virtual machines
Guarding against phishing attacks
Encrypting data at rest
WHAT THE MEANING OF CLI?
control command line
command line interface
central line Interface
command line intranet
WHAT THE MEANING OF GUI
Graphical User Internet
Graphical Union Interface
Grep Universal Interface
Graphical User Interface
................................ is way to run multiple operating systems and user applications on the same hardware
Virtualization
Storage
Data Warehousing
Data Mining
Type 1 Hypervisor.......................
Type 2 Hypervisor .......................
also called bare metal or native
also known as hosted hypervisors
also known as hosted hypervisors
also called bare metal or native
also called as full virtualization
also called as new virualization
None of the above
An Operating System is a program that helps the user to communicate between the software and ___________
Memory
Hardware
Alice told her friend Bob about her email password. And then she found Bob changed some her emails and sent emails to others. What traids are involved into this case?
Confidentially and Integrity
Integrity and Availability
Confidentally and Availability
Confidentally, Integrity and Availability
The process of converting a ciphertext into plaintext.
encryption
decryption
plaintext
cryptography
If your friend asks you to share your password to use your computer for work, what should you do?
Being your friend, you share the password
You decline to provide
You login yourself and allow him to work
You create his login on your computer
Turning off the GPS functions on your smartphone prevents any tracking of your phone’s location.?
True
False
Which of these isn't a cyber crime?
Accessing unauthorized data/ using someone's computer without permission
Tricking people into downloading malware
Accessing the DarkWeb
Creating an account on something you're not old enough for
What is meant by non-repudiation?
If a user does something, they can't later claim that they didn't do it.
Controls to protect the organization's reputation from harm due to inappropriate social media postings by employees, even if on their private accounts and personal time.
It is part of the rules set by administrative controls.
It is a security feature that prevents session replay attacks.
The concept of "secrecy" is most related to which foundational aspect of security?
Confidentiality
Integrity
Availability
Plausibility
Which of the following is an example of a "something you are" authentication factor?
A credit card presented to a cash machine
Your password and PIN
A user ID
A photograph of your face
What are the three pillars of information assurance?
Identification, Authentication, Non-repudiation
Data, User, Infrastructure
Confidentiality, Integrity, Availability
PII, PHI, Sensitive information
Sensitivity is a measure of the ...?
… pertinence assigned to information by its owner, or the purpose of representing its need for urgency.
… importance assigned to information by its owner, or the purpose of representing its need for protection.
… urgency and protection assigned to information by its owner.
… protection and timeliness assigned to information by its owner, or the purpose of representing its need for urgency.
The process of verifying or proving the user's identification is known as:?
Confidentiality
Authentication
Authorization
Identification
Which of the following Cybersecurity concepts guarantees that information is accessible only to those authorized to access it?
Non-repudiation
Authentication
Confidentiality
Accessibility
A USB pen with data passed around the office is an example of:?
Data in transit
Data at rest
Data in use
Data in motion
Passport, ID card, and security token are examples of:?
Multi-factor Authentication
Something you have
Something you are
Something you know
A file that is open is an example of:?
Data in motion
Data in storage
Data during processing
Data open
You try to install a program, but the system tells you that only administrators can do that, you probably don't have enough?
Authentication
Non-repudiation
Availability
Authorization
What does this padlock sign mean in the address bar of your browser?
The site is secure and data is transmitted using SSL
There is a padlock available for purchase
The website does not include "safety locks"
The page is locked down for some odd reason
Asymmetric encryption uses only 1 key.
True
False
Maybe
God Knows
What do we call unscrambled, readable data?
ASCII
Ciphertext
Plaintext
Purple prose
How does asymmetric encryption differ from symmetric encryption?
Asymmetric encryption uses the same key for both encryption and decryption
Asymmetric encryption uses different keys for encryption and decryption
Asymmetric encryption is only used for data storage
Asymmetric encryption is less secure than symmetric encryption
How can DDoS attacks be prevented?
Ignoring the issue and hoping it goes away on its own
Allowing all incoming traffic without any filtering
Installing more servers to handle the traffic
Using firewalls, intrusion detection systems, and load balancers to filter and manage incoming traffic
What is a common method for detecting DDoS attacks?
Scanning for viruses
Analyzing server logs
Monitoring network traffic
Updating software patches
What is the difference between a DoS and a DDoS attack?
A DoS attack is carried out by a group of hackers, while a DDoS attack is carried out by a single hacker.
A DoS attack is more difficult to detect than a DDoS attack.
A DDoS attack is less harmful than a DoS attack.
A DoS attack is carried out by a single source, while a DDoS attack is carried out by multiple sources.
How can businesses prepare for potential DDoS attacks?
Only focusing on cybersecurity after an attack has already occurred
Hiring more salespeople to increase revenue
Ignoring the potential threat and hoping it never happens
Implementing DDoS protection solutions, regularly testing network infrastructure, and having a response plan in place
Malicious emails that aim to attack company executives are an example of:?
DDOS
Spear phishing
Phishing
Whaling
An Internet Service Provider (ISP)
is a web page
is a web browser
provides access to internet
Funds access to the internet for 3rd World CountriesThis is a wrong answer
Which connection type is a wireless method of sending information using radio waves?
Fibre optic
Wi-Fi
Broadband
Cable
What are the upper layers of the OSI layer?
Transfer
Data link and network
Application, presentation, and session
Physical, data link and network
It is a number identifying of a computer or another device on the Internet
Machine Language
Binary Number
IP Address
Signal
It is small network constrained to a small geographic area.
LAN
MAN
PAN
WAN
For a Class C IPv4 Address, how many usable hosts are there by default?
254
64516
65536
255
32768
What is the default subent mask for the Class C network?
255.255.254.0
255.255.252.0
255.255.255.128
255.255.255.0
HTTP stands for..
.. Hyper Technology Transmission Piece
Hypertext Transfer Protocol
Hypertext Talking Package
Hypertext Transfer Program
MODEM is
Modulation Demodulation
Modulator Demodulator
Model Demodulator
What is layer 6 of the OSI model?
Spooky
Presentation
Session
Transport
What does TCP guarantee?
delivery of data and packets delivered in the right order
the route data will take
fast, low latency delivery of data
safe data without viruses
