NEW
Font size
WorksheetsCybersecurity Unit 1 Review Part 2
Total questions: 74
Worksheet time: 37mins
What is essential in forensic analysis with information and data to ensure there is no doubt that it was tampered with?
Non-repudiation
Encryption
Data masking
Data compression
What must be available to verify the earliest state of the data in digital forensics?
Encryption key
Provenance
Data masking
Data compression
What is the AAA Framework used to understand?
Security surrounding the accessibility of individuals
Network performance
Data encryption methods
Software development processes
Which of the following is NOT a part of the AAA Framework's process of identification?
Authentication
Authorization
Accounting
Auditing
Which of the following is an example of a knowledge-based method for authentication?
Key cards
Fingerprint recognition
Passwords
Tokens
What type of authentication method involves the use of key cards, tokens, or smart cards?
Knowledge-based
Possession-based
Biometric
Multi-factor
Which of the following is a biometric method of authentication?
Security questions
Key cards
Fingerprint recognition
Passwords
What does multi-factor authentication involve?
Using passwords and pins
Using key cards and tokens
Using fingerprint and face recognition
Combination of two or more listed methods
What is the primary purpose of the AAA Framework in authenticating systems?
To ensure data encryption
To verify the identity of a device, computer, or application
To manage network traffic
To provide data storage solutions
Which of the following is an example of Credential-Based authentication?
Fingerprinting
Hardware tokens
Username and password
Client and server authentication
What type of authentication uses fingerprinting or behavioral metrics?
Credential-Based
Token-Based
Biometric
Mutual
Which authentication method involves client and server authentication?
Credential-Based
Token-Based
Biometric
Mutual
What does Zero-Trust Architecture assume about systems?
All systems are trustworthy
No system is trustworthy
Only external systems are trustworthy
Only internal systems are trustworthy
What does the AAA Framework - Authorization Models govern?
Who can access and what actions can they perform within a system
The speed of data processing
The type of data stored in a system
The physical location of servers
Which of the following is NOT a factor that determines the AAA Framework - Authorization Models?
System complexity
Data sensitivity
Compliance requirements
User interface design
Which factor in the AAA Framework - Authorization Models deals with the importance of data protection?
System complexity
Data sensitivity
Compliance requirements
Management
What is one of the factors that determine the AAA Framework - Authorization Models?
Network speed
System complexity
User experience
Hardware specifications
Which authorization model assigns permissions directly to people or groups?
Role-Based Access Control (RBAC)
Attribute-Based Access Control (ABAC)
Access Control Lists (ACL)
Mandatory Access Control (MAC)
Which authorization model is well-suited for complex systems with dynamic needs?
Role-Based Access Control (RBAC)
Attribute-Based Access Control (ABAC)
Access Control Lists (ACL)
Discretionary Access Control (DAC)
Which authorization model assigns permissions based on roles and users are assigned these roles?
Role-Based Access Control (RBAC)
Attribute-Based Access Control (ABAC)
Access Control Lists (ACL)
Mandatory Access Control (MAC)
Which of the following is an example of Role-Based Access Control (RBAC)?
Assigning permissions based on department
Assigning permissions directly to people
Assigning permissions based on roles such as administrators, guests, editors
Assigning permissions based on device type
What does Rule-Based Access Control (RuBAC) primarily use to define access conditions?
Security labels
If-then statements
User roles
Access lists
Which of the following is a characteristic of Mandatory Access Control (MAC)?
User-defined access rules
High flexibility for user needs
Centrally controlled and often used in high-security environments
Low protection levels
Which access control model allows specific security requirements?
Discretionary Access Control (DAC)
Role-Based Access Control (RBAC)
Rule-Based Access Control (RuBAC)
Mandatory Access Control (MAC)
What is a disadvantage of Mandatory Access Control (MAC)?
Low protection levels
Less flexible for user needs
User-defined access rules
Allows specific security requirements
Which of the following is NOT a factor used in Multi-Factor Authentication?
Something you know
Something you have
Something you are
Something you see
What is an example of an inexpensive method for Multi-Factor Authentication?
Separate hardware tokens
Specialized scanning equipment
Free smartphone applications
Biometric scanners
Which of the following can make Multi-Factor Authentication expensive?
Free smartphone applications
Separate hardware tokens
Passwords
Security questions
Which of the following is a factor that can be used in Multi-Factor Authentication?
Something you know
Something you see
Something you hear
Something you touch
What does MFA stand for in the context of security?
Multi-Factor Authentication
Multi-Form Authentication
Multiple-Factor Authorization
Multi-Form Authorization
Which of the following is NOT a benefit of implementing MFA?
Enhanced security by adding layers beyond traditional username and password
If one factor is compromised, additional factors add a layer of protection
Often required by regulatory standards
Reduces the need for passwords entirely
Which of the following is an example of a factor used in MFA?
Password
Biometrics
Username
Email address
Why is MFA often required by regulatory standards?
To reduce the cost of security systems
To enhance security by adding multiple layers of protection
To simplify the login process
To eliminate the need for passwords
Which of the following is NOT an example of a factor used in MFA?
Biometrics
Authentication Tokens
Security keys
Username
What is a common authentication factor that is a secret word or phrase?
PIN
Password
Pattern
Token
What does PIN stand for?
Personal Identification Number
Private Identification Number
Public Identification Number
Personal Information Number
Which of the following is NOT typically contained anywhere on a smart card or ATM card?
Password
PIN
Pattern
Token
What type of authentication involves completing a series of patterns?
Password
PIN
Pattern
Token
Which of the following integrates with devices and may require a PIN?
USB token
Smart card
Hardware or software tokens
Your phone
What is a characteristic of a USB token?
Integrates with devices
Generates pseudo-random authentication codes
Certificate is on the USB device
SMS a code to your phone
Which of the following generates pseudo-random authentication codes?
Smart card
USB token
Hardware or software tokens
Your phone
How does your phone contribute to authentication according to the document?
Integrates with devices
Certificate is on the USB device
Generates pseudo-random authentication codes
SMS a code to your phone
Which of the following is an example of biometric authentication?
Password
Fingerprint
Security question
PIN
What does biometric authentication usually store?
The actual fingerprint
A mathematical representation of your biometric
A copy of your fingerprint
A photograph of your fingerprint
Why is biometric authentication difficult to change?
You can change your fingerprint easily
You can't change your fingerprint
You can change your password easily
You can't change your password
In what kind of situations is biometric authentication used?
Everyday situations
Very specific situations
General situations
All situations
Which of the following statements is true about biometric authentication?
It is foolproof
It is not foolproof
It is always accurate
It is never accurate
What is required for a transaction to complete based on your location?
The transaction only completes if you are in a particular geographic location
The transaction completes regardless of your location
The transaction only completes if you are connected to a specific network
The transaction completes only during specific times of the day
Which IP version is mentioned as not working well with location-based factors?
IPv4
IPv6
IPv2
IPv5
What is a requirement for mobile device location services to work effectively?
Must be in a location that can receive GPS information or near an identified mobile or 802.11 network
Must be connected to a wired network
Must be in a location with no GPS signal
Must be in a location with no network connectivity
What is a limitation of using IP addresses for location-based factors?
They are perfect identifiers of location
They do not work with IPv4
They are not perfect but can help provide more info
They are only used for identifying devices, not locations
What is required for on-premises location-based factors?
Must be on-site to log into a system
Must be connected to a VPN
Must be using a mobile device
Must be in a specific country
What is the primary goal of password attacks?
To gain a target’s password to log in as that target
To delete a target’s account
To create a new password for the target
To encrypt the target’s password
What is the most obvious way for a malicious person to get someone’s password?
By having the plaintext or unencrypted password
By guessing the password
By using a password manager
By creating a new password
Which of the following is NOT a method of gaining unencrypted passwords?
Intercepting an email meant for someone else that has a password in it
A keylogger capturing keystrokes as a target types in a password
Data breaches of passwords stored in plaintext
Using a password manager
What precaution should you take regarding plaintext passwords?
Never write down, type out, or store plaintext passwords unless absolutely necessary
Always share plaintext passwords with trusted friends
Store plaintext passwords in a secure folder
Write down plaintext passwords in a notebook
Which of the following is NOT a method for trying to figure out passwords covered in the Security+ objectives?
Brute Force
Dictionary Attacks
Spraying
Phishing
Which method for trying to figure out passwords is optional according to the lesson?
Brute Force
Dictionary Attacks
Spraying
Rainbow Attack
What is a characteristic of a brute force attack?
It is very fast.
It tries every combination and permutation until the right guess works.
It does not work on passwords.
It is always successful on the first attempt.
What is a disadvantage of a brute force attack?
It is very slow.
It is very fast.
It is always successful.
It does not require any resources.
What can happen to a brute force attack when attempted online?
It will always succeed.
It can be subject to failed logon restrictions.
It will never be detected.
It will lock you out immediately.
What is true about brute force attacks attempted offline?
They will lock you out.
They will not lock you out.
They are faster than online attacks.
They are always unsuccessful.
What is a dictionary attack?
A method of guessing passwords by trying every possible combination.
A faster form of brute force that uses commonly used words or passwords from a list.
A technique to encrypt passwords.
A way to store passwords securely.
What type of passwords are dictionary attacks most effective against?
Complex passwords
Long passwords
Simplistic or weak passwords
Encrypted passwords
How can one combat dictionary attacks?
By using short passwords
By using commonly used words
By enforcing strong password criteria (complexity, length, reuse, etc.)
By storing passwords in plain text
What is a key difference between dictionary attacks and brute force attacks?
Dictionary attacks try every possible combination.
Brute force attacks use a list of commonly used words.
Dictionary attacks don’t try every combination, only what’s on the list.
Brute force attacks are faster than dictionary attacks.
What resources are often used in dictionary attacks?
Encrypted password files
Wordlists of cracked or leaked password files from old cyber attacks
Randomly generated passwords
Passwords stored in secure databases
What is password spraying?
A technique involving trying a small set of commonly used passwords across numerous accounts.
A method of using a comprehensive dictionary to guess passwords.
A way to lock accounts by entering incorrect passwords multiple times.
A technique to encrypt passwords for security.
Why might a malicious user resort to password spraying?
They have unlimited attempts at a password.
They lack the time for a comprehensive dictionary attack.
They want to encrypt the password.
They want to create a new password.
What is an example of a password an attacker might use if they know a user's fondness for birds?
'password123'
'goldfinch'
'123456'
'qwerty'
What is one advantage of password spraying over other methods?
It is the most efficient method.
It avoids account lockouts.
It guarantees password guessing success.
It uses a comprehensive dictionary.
What is a rainbow table?
A table used for storing encrypted passwords
A precalculated series of hashes using known algorithms commonly used for cracking passwords
A table used for organizing data in a database
A method for encrypting data
How can an attacker use a rainbow table to find a plaintext password?
By decrypting the hash directly
By finding the matching hash and looking up the input text that produced that result
By guessing the password repeatedly
By using a brute force attack
Against which type of passwords and hashing algorithms are rainbow tables particularly effective?
Strong passwords and complex hashing algorithms
Weaker passwords and hashing algorithms
Encrypted passwords
Passwords stored in plain text
