wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Cybersecurity Unit 1 Review Part 2

Total questions: 74

Worksheet time: 37mins

Name
Class
Date
1.

What is essential in forensic analysis with information and data to ensure there is no doubt that it was tampered with?

a)

Non-repudiation

b)

Encryption

c)

Data masking

d)

Data compression

2.

What must be available to verify the earliest state of the data in digital forensics?

a)

Encryption key

b)

Provenance

c)

Data masking

d)

Data compression

3.

What is the AAA Framework used to understand?

a)

Security surrounding the accessibility of individuals

b)

Network performance

c)

Data encryption methods

d)

Software development processes

4.

Which of the following is NOT a part of the AAA Framework's process of identification?

a)

Authentication

b)

Authorization

c)

Accounting

d)

Auditing

5.

Which of the following is an example of a knowledge-based method for authentication?

a)

Key cards

b)

Fingerprint recognition

c)

Passwords

d)

Tokens

6.

What type of authentication method involves the use of key cards, tokens, or smart cards?

a)

Knowledge-based

b)

Possession-based

c)

Biometric

d)

Multi-factor

7.

Which of the following is a biometric method of authentication?

a)

Security questions

b)

Key cards

c)

Fingerprint recognition

d)

Passwords

8.

What does multi-factor authentication involve?

a)

Using passwords and pins

b)

Using key cards and tokens

c)

Using fingerprint and face recognition

d)

Combination of two or more listed methods

9.

What is the primary purpose of the AAA Framework in authenticating systems?

a)

To ensure data encryption

b)

To verify the identity of a device, computer, or application

c)

To manage network traffic

d)

To provide data storage solutions

10.

Which of the following is an example of Credential-Based authentication?

a)

Fingerprinting

b)

Hardware tokens

c)

Username and password

d)

Client and server authentication

11.

What type of authentication uses fingerprinting or behavioral metrics?

a)

Credential-Based

b)

Token-Based

c)

Biometric

d)

Mutual

12.

Which authentication method involves client and server authentication?

a)

Credential-Based

b)

Token-Based

c)

Biometric

d)

Mutual

13.

What does Zero-Trust Architecture assume about systems?

a)

All systems are trustworthy

b)

No system is trustworthy

c)

Only external systems are trustworthy

d)

Only internal systems are trustworthy

14.

What does the AAA Framework - Authorization Models govern?

a)

Who can access and what actions can they perform within a system

b)

The speed of data processing

c)

The type of data stored in a system

d)

The physical location of servers

15.

Which of the following is NOT a factor that determines the AAA Framework - Authorization Models?

a)

System complexity

b)

Data sensitivity

c)

Compliance requirements

d)

User interface design

16.

Which factor in the AAA Framework - Authorization Models deals with the importance of data protection?

a)

System complexity

b)

Data sensitivity

c)

Compliance requirements

d)

Management

17.

What is one of the factors that determine the AAA Framework - Authorization Models?

a)

Network speed

b)

System complexity

c)

User experience

d)

Hardware specifications

18.

Which authorization model assigns permissions directly to people or groups?

a)

Role-Based Access Control (RBAC)

b)

Attribute-Based Access Control (ABAC)

c)

Access Control Lists (ACL)

d)

Mandatory Access Control (MAC)

19.

Which authorization model is well-suited for complex systems with dynamic needs?

a)

Role-Based Access Control (RBAC)

b)

Attribute-Based Access Control (ABAC)

c)

Access Control Lists (ACL)

d)

Discretionary Access Control (DAC)

20.

Which authorization model assigns permissions based on roles and users are assigned these roles?

a)

Role-Based Access Control (RBAC)

b)

Attribute-Based Access Control (ABAC)

c)

Access Control Lists (ACL)

d)

Mandatory Access Control (MAC)

21.

Which of the following is an example of Role-Based Access Control (RBAC)?

a)

Assigning permissions based on department

b)

Assigning permissions directly to people

c)

Assigning permissions based on roles such as administrators, guests, editors

d)

Assigning permissions based on device type

22.

What does Rule-Based Access Control (RuBAC) primarily use to define access conditions?

a)

Security labels

b)

If-then statements

c)

User roles

d)

Access lists

23.

Which of the following is a characteristic of Mandatory Access Control (MAC)?

a)

User-defined access rules

b)

High flexibility for user needs

c)

Centrally controlled and often used in high-security environments

d)

Low protection levels

24.

Which access control model allows specific security requirements?

a)

Discretionary Access Control (DAC)

b)

Role-Based Access Control (RBAC)

c)

Rule-Based Access Control (RuBAC)

d)

Mandatory Access Control (MAC)

25.

What is a disadvantage of Mandatory Access Control (MAC)?

a)

Low protection levels

b)

Less flexible for user needs

c)

User-defined access rules

d)

Allows specific security requirements

26.

Which of the following is NOT a factor used in Multi-Factor Authentication?

a)

Something you know

b)

Something you have

c)

Something you are

d)

Something you see

27.

What is an example of an inexpensive method for Multi-Factor Authentication?

a)

Separate hardware tokens

b)

Specialized scanning equipment

c)

Free smartphone applications

d)

Biometric scanners

28.

Which of the following can make Multi-Factor Authentication expensive?

a)

Free smartphone applications

b)

Separate hardware tokens

c)

Passwords

d)

Security questions

29.

Which of the following is a factor that can be used in Multi-Factor Authentication?

a)

Something you know

b)

Something you see

c)

Something you hear

d)

Something you touch

30.

What does MFA stand for in the context of security?

a)

Multi-Factor Authentication

b)

Multi-Form Authentication

c)

Multiple-Factor Authorization

d)

Multi-Form Authorization

31.

Which of the following is NOT a benefit of implementing MFA?

a)

Enhanced security by adding layers beyond traditional username and password

b)

If one factor is compromised, additional factors add a layer of protection

c)

Often required by regulatory standards

d)

Reduces the need for passwords entirely

32.

Which of the following is an example of a factor used in MFA?

a)

Password

b)

Biometrics

c)

Username

d)

Email address

33.

Why is MFA often required by regulatory standards?

a)

To reduce the cost of security systems

b)

To enhance security by adding multiple layers of protection

c)

To simplify the login process

d)

To eliminate the need for passwords

34.

Which of the following is NOT an example of a factor used in MFA?

a)

Biometrics

b)

Authentication Tokens

c)

Security keys

d)

Username

35.

What is a common authentication factor that is a secret word or phrase?

a)

PIN

b)

Password

c)

Pattern

d)

Token

36.

What does PIN stand for?

a)

Personal Identification Number

b)

Private Identification Number

c)

Public Identification Number

d)

Personal Information Number

37.

Which of the following is NOT typically contained anywhere on a smart card or ATM card?

a)

Password

b)

PIN

c)

Pattern

d)

Token

38.

What type of authentication involves completing a series of patterns?

a)

Password

b)

PIN

c)

Pattern

d)

Token

39.

Which of the following integrates with devices and may require a PIN?

a)

USB token

b)

Smart card

c)

Hardware or software tokens

d)

Your phone

40.

What is a characteristic of a USB token?

a)

Integrates with devices

b)

Generates pseudo-random authentication codes

c)

Certificate is on the USB device

d)

SMS a code to your phone

41.

Which of the following generates pseudo-random authentication codes?

a)

Smart card

b)

USB token

c)

Hardware or software tokens

d)

Your phone

42.

How does your phone contribute to authentication according to the document?

a)

Integrates with devices

b)

Certificate is on the USB device

c)

Generates pseudo-random authentication codes

d)

SMS a code to your phone

43.

Which of the following is an example of biometric authentication?

a)

Password

b)

Fingerprint

c)

Security question

d)

PIN

44.

What does biometric authentication usually store?

a)

The actual fingerprint

b)

A mathematical representation of your biometric

c)

A copy of your fingerprint

d)

A photograph of your fingerprint

45.

Why is biometric authentication difficult to change?

a)

You can change your fingerprint easily

b)

You can't change your fingerprint

c)

You can change your password easily

d)

You can't change your password

46.

In what kind of situations is biometric authentication used?

a)

Everyday situations

b)

Very specific situations

c)

General situations

d)

All situations

47.

Which of the following statements is true about biometric authentication?

a)

It is foolproof

b)

It is not foolproof

c)

It is always accurate

d)

It is never accurate

48.

What is required for a transaction to complete based on your location?

a)

The transaction only completes if you are in a particular geographic location

b)

The transaction completes regardless of your location

c)

The transaction only completes if you are connected to a specific network

d)

The transaction completes only during specific times of the day

49.

Which IP version is mentioned as not working well with location-based factors?

a)

IPv4

b)

IPv6

c)

IPv2

d)

IPv5

50.

What is a requirement for mobile device location services to work effectively?

a)

Must be in a location that can receive GPS information or near an identified mobile or 802.11 network

b)

Must be connected to a wired network

c)

Must be in a location with no GPS signal

d)

Must be in a location with no network connectivity

51.

What is a limitation of using IP addresses for location-based factors?

a)

They are perfect identifiers of location

b)

They do not work with IPv4

c)

They are not perfect but can help provide more info

d)

They are only used for identifying devices, not locations

52.

What is required for on-premises location-based factors?

a)

Must be on-site to log into a system

b)

Must be connected to a VPN

c)

Must be using a mobile device

d)

Must be in a specific country

53.

What is the primary goal of password attacks?

a)

To gain a target’s password to log in as that target

b)

To delete a target’s account

c)

To create a new password for the target

d)

To encrypt the target’s password

54.

What is the most obvious way for a malicious person to get someone’s password?

a)

By having the plaintext or unencrypted password

b)

By guessing the password

c)

By using a password manager

d)

By creating a new password

55.

Which of the following is NOT a method of gaining unencrypted passwords?

a)

Intercepting an email meant for someone else that has a password in it

b)

A keylogger capturing keystrokes as a target types in a password

c)

Data breaches of passwords stored in plaintext

d)

Using a password manager

56.

What precaution should you take regarding plaintext passwords?

a)

Never write down, type out, or store plaintext passwords unless absolutely necessary

b)

Always share plaintext passwords with trusted friends

c)

Store plaintext passwords in a secure folder

d)

Write down plaintext passwords in a notebook

57.

Which of the following is NOT a method for trying to figure out passwords covered in the Security+ objectives?

a)

Brute Force

b)

Dictionary Attacks

c)

Spraying

d)

Phishing

58.

Which method for trying to figure out passwords is optional according to the lesson?

a)

Brute Force

b)

Dictionary Attacks

c)

Spraying

d)

Rainbow Attack

59.

What is a characteristic of a brute force attack?

a)

It is very fast.

b)

It tries every combination and permutation until the right guess works.

c)

It does not work on passwords.

d)

It is always successful on the first attempt.

60.

What is a disadvantage of a brute force attack?

a)

It is very slow.

b)

It is very fast.

c)

It is always successful.

d)

It does not require any resources.

61.

What can happen to a brute force attack when attempted online?

a)

It will always succeed.

b)

It can be subject to failed logon restrictions.

c)

It will never be detected.

d)

It will lock you out immediately.

62.

What is true about brute force attacks attempted offline?

a)

They will lock you out.

b)

They will not lock you out.

c)

They are faster than online attacks.

d)

They are always unsuccessful.

63.

What is a dictionary attack?

a)

A method of guessing passwords by trying every possible combination.

b)

A faster form of brute force that uses commonly used words or passwords from a list.

c)

A technique to encrypt passwords.

d)

A way to store passwords securely.

64.

What type of passwords are dictionary attacks most effective against?

a)

Complex passwords

b)

Long passwords

c)

Simplistic or weak passwords

d)

Encrypted passwords

65.

How can one combat dictionary attacks?

a)

By using short passwords

b)

By using commonly used words

c)

By enforcing strong password criteria (complexity, length, reuse, etc.)

d)

By storing passwords in plain text

66.

What is a key difference between dictionary attacks and brute force attacks?

a)

Dictionary attacks try every possible combination.

b)

Brute force attacks use a list of commonly used words.

c)

Dictionary attacks don’t try every combination, only what’s on the list.

d)

Brute force attacks are faster than dictionary attacks.

67.

What resources are often used in dictionary attacks?

a)

Encrypted password files

b)

Wordlists of cracked or leaked password files from old cyber attacks

c)

Randomly generated passwords

d)

Passwords stored in secure databases

68.

What is password spraying?

a)

A technique involving trying a small set of commonly used passwords across numerous accounts.

b)

A method of using a comprehensive dictionary to guess passwords.

c)

A way to lock accounts by entering incorrect passwords multiple times.

d)

A technique to encrypt passwords for security.

69.

Why might a malicious user resort to password spraying?

a)

They have unlimited attempts at a password.

b)

They lack the time for a comprehensive dictionary attack.

c)

They want to encrypt the password.

d)

They want to create a new password.

70.

What is an example of a password an attacker might use if they know a user's fondness for birds?

a)

'password123'

b)

'goldfinch'

c)

'123456'

d)

'qwerty'

71.

What is one advantage of password spraying over other methods?

a)

It is the most efficient method.

b)

It avoids account lockouts.

c)

It guarantees password guessing success.

d)

It uses a comprehensive dictionary.

72.

What is a rainbow table?

a)

A table used for storing encrypted passwords

b)

A precalculated series of hashes using known algorithms commonly used for cracking passwords

c)

A table used for organizing data in a database

d)

A method for encrypting data

73.

How can an attacker use a rainbow table to find a plaintext password?

a)

By decrypting the hash directly

b)

By finding the matching hash and looking up the input text that produced that result

c)

By guessing the password repeatedly

d)

By using a brute force attack

74.

Against which type of passwords and hashing algorithms are rainbow tables particularly effective?

a)

Strong passwords and complex hashing algorithms

b)

Weaker passwords and hashing algorithms

c)

Encrypted passwords

d)

Passwords stored in plain text