wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Chapter Eight Practice Quiz - Info Sec

Total questions: 65

Worksheet time: 33mins

Name
Class
Date
1.

What is often referred to as the "weak link" in information security?

a)

Firewalls

b)

Antivirus software

c)

People

d)

Encryption methods

2.

What type of attack relies on manipulating people to gain information or access to facilities?

a)

Phishing

b)

Social engineering

c)

Malware

d)

Denial of Service

3.

Which of the following is NOT a common tactic used in social engineering attacks?

a)

Sending sensitive information via unprotected channels

b)

Handing over passwords

c)

Posting important data in conspicuous places

d)

Using strong encryption methods

4.

What is a social engineering attack where an attacker calls in a panicked voice and asks for sensitive information?

a)

Phishing

b)

Pretexting

c)

Baiting

d)

Tailgating

5.

What are the two primary sources of information to look at when protecting people and commercial organizations?

a)

Human intelligence and open source intelligence

b)

Firewalls and antivirus software

c)

Encryption methods and secure passwords

d)

Physical security and network security

6.

What is Human Intelligence (HUMINT)?

a)

Data gathered from electronic devices

b)

Data gathered by talking to people

c)

Data gathered from social media

d)

Data gathered from job postings

7.

Which of the following is NOT a method to collect HUMINT?

a)

Observing people's schedules

b)

Using torture

c)

Tricking participants with scams

d)

Analyzing job postings

8.

What is Open Source Intelligence (OSINT)?

a)

Information collected from publicly available sources

b)

Information collected from private conversations

c)

Information collected from encrypted databases

d)

Information collected from physical surveillance

9.

Which of the following is a primary source of information for social engineering attacks?

a)

Encrypted emails

b)

Job postings

c)

Private conversations

d)

Physical surveillance

10.

What can attackers use to set up social engineering attacks based on a target's skills or interests?

a)

Résumés

b)

Encrypted emails

c)

Private conversations

d)

Physical surveillance

11.

How can attackers use social media for OSINT?

a)

By hacking into private accounts

b)

By following someone's activities and social contacts

c)

By accessing encrypted databases

d)

By conducting physical surveillance

12.

What example is provided in the text to illustrate how attackers can take advantage of social media tools?

a)

The 2016 US presidential election

b)

The 2020 US presidential election

c)

The 2012 US presidential election

d)

The 2008 US presidential election

13.

How many Facebook ads did the Russian-based company Internet Research Agency purchase to incite tensions during the 2016 US presidential election?

a)

1,500

b)

2,500

c)

3,500

d)

4,500

14.

What type of records can provide a wealth of information about a target, including evidence of mortgages, marriages, divorces, legal proceedings, and parking tickets?

a)

Social media records

b)

Public records

c)

Private records

d)

Financial records

15.

Which search engine is mentioned as an excellent resource for information gathering, particularly when attackers make use of advanced search operators?

a)

Bing

b)

Yahoo

c)

Google

d)

DuckDuckGo

16.

What does the search operator "filetype:pdf" do?

a)

Limits results to a specific site

b)

Finds pages containing a word or words in the URL

c)

Limits results to a specific file type

d)

Finds pages containing a word or words

17.

What is the purpose of the Google Hacking Database mentioned in the text?

a)

To store personal information

b)

To find specific vulnerabilities or security issues

c)

To hack into Google accounts

d)

To create new search engines

18.

What type of data can file metadata reveal?

a)

Only timestamps and file statistics

b)

Only usernames and server names

c)

Timestamps, file statistics, usernames, server names, network file paths, and deleted or updated information

d)

Only network file paths and deleted information

19.

Which tool is mentioned as being able to view and edit EXIF data?

a)

EnCase

b)

Shodan

c)

Maltego

d)

Exiftool

20.

What kind of information might image files produced by devices containing GPS information include?

a)

Only timestamps

b)

Location coordinates

c)

File statistics

d)

Network file paths

21.

What is Shodan primarily used for?

a)

Editing image files

b)

Searching for information saved on internet-connected devices

c)

Recovering deleted files

d)

Viewing EXIF data

22.

Which of the following is a web-based search engine that looks for information saved on internet-connected devices?

a)

EnCase

b)

Exiftool

c)

Shodan

d)

Maltego

23.

What is the purpose of using transforms in intelligence-gathering tools like Maltego?

a)

To discover information related to information that you already have.

b)

To encrypt data for secure communication.

c)

To delete unnecessary data from the database.

d)

To create new data from scratch.

24.

What kind of intelligence is gathered from geographical information, typically from satellites?

a)

Geospatial intelligence (GEOINT)

b)

Signals intelligence (SIGINT)

c)

Technical intelligence (TECHINT)

d)

Financial intelligence (FININT)

25.

Which type of intelligence involves data gathered by intercepting signals between people or systems?

a)

Signals intelligence (SIGINT)

b)

Technical intelligence (TECHINT)

c)

Financial intelligence (FININT)

d)

Cyber intelligence (CYBINT)

26.

What does MASINT stand for?

a)

Measurement and signature intelligence

b)

Military and strategic intelligence

c)

Management and security intelligence

d)

Measurement and security intelligence

27.

Which type of intelligence is often acquired from financial institutions?

a)

Financial intelligence (FININT)

b)

Technical intelligence (TECHINT)

c)

Geospatial intelligence (GEOINT)

d)

Cyber intelligence (CYBINT)

28.

What is the primary focus of technical intelligence (TECHINT)?

a)

Equipment, technology, and weapons

b)

Financial transactions

c)

Geographical information

d)

Social engineering attacks

29.

What is pretexting in the context of social engineering?

a)

Using gathered information to assume a fake identity and convince targets to give up sensitive information.

b)

Sending unsolicited emails to collect personal information.

c)

Creating fake websites to trick users into providing personal information.

d)

Installing malware on a target's system through malicious links.

30.

Which type of interaction requires a heightened level of attention to details such as body language?

a)

Indirect encounters

b)

Face-to-face encounters

c)

Email interactions

d)

Texting

31.

What advantage does pretexting give social engineers?

a)

Ability to create fake websites

b)

Ability to drop names and provide details about the organization

c)

Ability to send unsolicited emails

d)

Ability to install malware on the target's system

32.

What is phishing?

a)

A technique where attackers use gathered information to assume a fake identity.

b)

A technique where attackers use electronic communications to collect personal information or install malware.

c)

A technique where attackers create fake websites to trick users.

d)

A technique where attackers send unsolicited emails to targets.

33.

What do fake sites used in web-based phishing attacks typically resemble?

a)

Government websites

b)

Well-known websites such as banking, social media, or shopping sites

c)

Personal blogs

d)

Educational websites

34.

What has improved security in recent years to render phishing attacks more difficult?

a)

Better antivirus software

b)

Improved browser security and warnings

c)

Increased public awareness

d)

Stricter email regulations

35.

What is spear phishing?

a)

A technique where attackers use gathered information to assume a fake identity.

b)

A technique where attackers use electronic communications to collect personal information or install malware.

c)

A targeted phishing attack against specific companies, organizations, or people.

d)

A technique where attackers create fake websites to trick users.

36.

What is the primary goal of spear phishing attacks?

a)

To trick a small percentage of recipients with poorly constructed emails

b)

To send clean emails containing expected logos and graphics

c)

To steal credentials and log the target into the real site

d)

To send mass emails to a large group of recipients

37.

What is physical tailgating in the context of security?

a)

Sending phishing emails to employees

b)

Following someone through an access control point without proper credentials

c)

Using technical tools to ensure strong passwords

d)

Conducting security training programs

38.

Which of the following is NOT a method used by attackers to aid in tailgating?

a)

Using props

b)

Employing psychology to gain sympathy

c)

Sending clean emails with expected logos

d)

Knowing which equipment to use

39.

What is the purpose of building security awareness with security training programs?

a)

To ensure employees use technical tools for strong passwords

b)

To conduct instructor-led or computer-based lessons followed by quizzes

c)

To allow attackers to play on the sympathies of others

d)

To send clean emails containing expected logos and graphics

40.

What is a challenge mentioned in the text regarding the use of technical tools for passwords?

a)

They are too expensive to implement

b)

They cannot easily control what users choose as passwords

c)

They are not effective in preventing tailgating

d)

They require extensive training programs

41.

What is one harmful behavior related to password usage mentioned in the text?

a)

Using the same password for multiple accounts

b)

Changing passwords frequently

c)

Using passwords with special characters

d)

Writing passwords in a notebook

42.

What should users be suspicious of according to the text?

a)

Emails from known contacts

b)

Unusual requests or emails in their inboxes

c)

Regular system updates

d)

Messages from their IT department

43.

What is one of the best ways to tackle poor password hygiene?

a)

Forcing users to change passwords monthly

b)

Educating users about creating strong passwords

c)

Using biometric authentication

d)

Disabling password requirements

44.

What should users do when faced with even the slightest doubt about an email or request?

a)

Ignore the email or request

b)

Trust the sender immediately

c)

Verify the authenticity of the email or request

d)

Forward the email to all contacts

45.

What is the potential consequence of an attacker compromising a password database?

a)

The attacker gains access to the user's email and decrypted password

b)

The user is forced to change their password

c)

The attacker is blocked from the system

d)

The user receives a warning message

46.

What is a common misconception uneducated users have about connecting to networks in different locations?

a)

They believe all networks are equally secure.

b)

They think connecting to a network in a hotel is safer than at home.

c)

They assume connecting to a network in a conference room at work is the same as connecting to a network in an airport.

d)

They believe connecting to a network in a coffee shop is more secure than at work.

47.

What should users be educated about to protect the enterprise network?

a)

How to connect their iPads to the production network.

b)

How to connect to any available network.

c)

Not allowing foreign devices to connect to the enterprise network.

d)

How to use any network without restrictions.

48.

What is a recommended solution to protect corporate resources on outside networks?

a)

Use any available network without restrictions.

b)

Implement a VPN that allows users to access the corporate network.

c)

Connect to the network at local coffee shops.

d)

Share sensitive data over public networks.

49.

What should users be taught to avoid when dealing with email attachments?

a)

Opening attachments from known contacts.

b)

Opening attachments containing file types like EXE, ZIP, and PDF.

c)

Opening attachments from people they don't know.

d)

Both B and C.

50.

Which of the following is NOT a red flag when surfing the web?

a)

Email attachments from people they don't know.

b)

Web links using shortened URLs such as bttp://bi.ly/.

c)

Web links with names that differ slightly from known ones.

d)

Web links from trusted sources.

51.

What should you do if you expect your users to follow the rules?

a)

Send an email to all users containing a link to a lengthy policy.

b)

Condense the most critical part of your policy into a kind of crib notes or highlights reel.

c)

Ignore the rules and hope users follow them.

d)

Only communicate the rules verbally.

52.

What is a clean desk policy?

a)

A policy that allows employees to leave sensitive information on their desks overnight.

b)

A policy that states sensitive information shouldn't be left unattended on a desk for any significant period of time.

c)

A policy that requires employees to clean their desks every day.

d)

A policy that allows employees to store sensitive information on their desks.

53.

How can you make a training presentation more engaging?

a)

By making the lecture portion longer.

b)

By conducting an interactive quiz show-style game on the material.

c)

By only using posters and newsletters.

d)

By avoiding any form of competition.

54.

What should you do to ensure employees use personal equipment properly in the workplace?

a)

Allow them to use it on the same network as the company's production systems.

b)

Set rules for when and how employees can use personal equipment.

c)

Allow them to use any device without restrictions.

d)

Ignore the use of personal equipment.

55.

What is one way to effectively communicate policies to users?

a)

Send a lengthy email and have them attest to having read it.

b)

Use posters, giveaways, and newsletters to present the information.

c)

Only use verbal communication.

d)

Avoid communicating policies altogether.

56.

Why are people the weak link in a security program?

a)

Because they can be easily replaced

b)

Because they can be targeted by social engineering attacks

c)

Because they are not important in security

d)

Because they are always careless

57.

Define tailgating. Why is it a problem?

a)

It is a type of phishing attack; it can steal data

b)

It is following someone into a restricted area; it can lead to unauthorized access

c)

It is a type of malware; it can damage systems

d)

It is a form of password attack; it can compromise accounts

58.

How can you more effectively reach users in your security awareness and training efforts?

a)

By using technical jargon

b)

By making the information engaging and relevant

c)

By ignoring their feedback

d)

By using complex training materials

59.

Why shouldn't you allow employees to attach personal equipment to your organization's network?

a)

It can slow down the network

b)

It can lead to unauthorized access and security breaches

c)

It can increase electricity usage

d)

It can make the network faster

60.

How might you train users to recognize phishing?

a)

By showing them examples of phishing emails

b)

By ignoring phishing threats

c)

By using only technical controls

d)

By not discussing phishing at all

61.

Why is it important not to use the same password for all your accounts?

a)

It makes it easier to remember passwords

b)

It reduces the risk of multiple accounts being compromised

c)

It makes logging in faster

d)

It is recommended by security experts

62.

What is pretexting?

a)

A type of malware

b)

A social engineering technique where an attacker creates a fabricated scenario to steal information

c)

A method of encrypting data

d)

A way to secure wireless networks

63.

Why might using the wireless network in a hotel with a corporate laptop be dangerous?

a)

It can be slow

b)

It can lead to data breaches and security risks

c)

It can be expensive

d)

It can improve network speed

64.

Why might clicking a shortened URL from a service such as bit.ly be dangerous?

a)

It can lead to unexpected websites and potential security threats

b)

It can make the URL longer

c)

It can improve website loading speed

d)

It can increase internet usage

65.

Why is it important to use strong passwords?

a)

To make them easy to remember

b)

To prevent unauthorized access and enhance security

c)

To make logging in faster

d)

To reduce the need for password changes