WorksheetsPhysical Security, Disruption/Deception Tech + 2024
Total questions: 56
Worksheet time: 28mins
What is the purpose of a mantrap in physical security?
To trap malicious users caught in sensitive areas
To get people on camera
To allow easy entry for emergency services
To control access to sensitive systems, areas, and information
Which of the following is NOT a type of biometric authentication?
Fingerprint scan
Iris recognition
Key card (RFID)
Facial recognition
What is a primary function of video surveillance (CCTV) in physical security?
To monitor employee performance
To detect environmental hazards
To observe and record activities around secure areas
To control access to sensitive information
Which type of access control system uses physical characteristics to grant access?
Keycard
PIN code
Biometrics
Security guard
Which component of physical security is responsible for tracking the distribution and use of keys?
Video Surveillance
Key Management
Security Guards
Alarms
What is the main function of environmental controls in a physical security plan?
To provide authentication for access
To protect against fire and flooding
To monitor employee behavior
o restrict access to unauthorized users
What type of lock system allows only authorized personnel to enter a secure area after an authentication process?
Mechanical lock
Electronic lock
Deadbolt
Combination lock
What is the role of security guards in a physical security strategy?
To manage access control systems
To monitor surveillance footage
To enforce security policies and respond to incidents
To conduct audits of security measures
Which of the following is an example of a physical barrier in security?
Password protection
Video surveillance
Fences and walls
Security policies
What should be done to mitigate internal threats to physical security?
Provide unrestricted access to all employees
Implement strict access controls and monitoring
Rely solely on video surveillance
Reduce the number of security guards
What is the main purpose of an alarm system in a physical security framework?
To provide access control
To deter potential intruders
To alert security personnel to unauthorized access or environmental threats
To monitor employee productivity
Which component is primarily responsible for ensuring the secure storage of sensitive information?
Alarms
Security Guards
Access Control
Environmental Controls
What type of physical security measure requires individuals to present an ID badge to enter a secure area?
Security Guards
Biometrics
Access Control
Locks
Which of the following describes a situation that may trigger an alarm in a secure facility?
A scheduled maintenance visit
A power outage
Unauthorized entry through a restricted door
Employees exiting the building
What is the purpose of a security audit in physical security?
To collect user data
To assess and improve security measures
To reduce security staff
To install surveillance cameras
Which physical security measure can help prevent unauthorized access to a server room?
Fire extinguishers
Mantraps
Employee training
Office signage
In what way can climate control systems contribute to physical security?
They restrict access to sensitive areas.
They prevent equipment failure due to environmental conditions.
They monitor employee behavior.
They assist in identifying internal threats.
Which component of physical security helps deter theft and vandalism in high-risk areas?
Security Guards
Access Control Systems
Video Surveillance
All of the above
What type of security is specifically aimed at protecting the physical assets of an organization?
Internet security
Information security
Physical security
Application security
Which of the following measures is least effective for protecting against environmental threats?
Fire suppression systems
Key management policies
Flood barriers
Climate control systems
What is the primary goal of using deception technologies in cybersecurity?
To secure sensitive data
To mislead attackers and gather intelligence
To replace traditional security measures
To enhance employee productivity
What is a honeypot?
A physical barrier for unauthorized access
A decoy system designed to lure and analyze attackers
A video surveillance system
A type of environmental control
What type of data can honeytokens be?
Real user credentials
Fake data used to detect unauthorized access
Employee performance metrics
Backup system configurations
Which of the following best describes a honeynet?
A single decoy system
A network of honeypots designed to gather intelligence on attackers
A data backup solution
A security guard monitoring system
What is the primary function of a honeyfile?
To provide secure storage for sensitive data
To serve as a decoy file that alerts when accessed by attackers
To track employee access to sensitive areas
To backup important documents
Why are deception technologies important in cybersecurity?
They eliminate the need for physical security.
They provide a real-time defense against malware.
They help detect and analyze attacker behavior.
They replace traditional firewalls.
Which of the following is NOT a characteristic of a honeypot?
It mimics real systems.
It is heavily monitored.
It has high production value.
It collects logs of attacker interactions.
What is the primary advantage of using a honeynet over a single honeypot?
Easier to manage
More comprehensive data collection
Lower cost
Simpler to deploy
What is the primary advantage of using a honeynet over a single honeypot?
Easier to manage
More comprehensive data collection
Lower cost
Simpler to deploy
What should be the primary focus when designing a honeytoken?
Complexity of the data
Realism of the data
Volume of data
Security of real data
Which scenario best illustrates the use of deception technologies?
An organization uses firewalls to block intrusions.
A company sets up fake login pages to capture attacker information.
Employees receive training on phishing attacks.
Antivirus software is installed on all systems.
What is a primary use of honeyfiles in a security strategy?
To provide secure access to files
To distract attackers from real data
To enhance employee productivity
To serve as backup storage
Which of the following best describes the concept of “deception” in cybersecurity?
Using advanced encryption methods
Implementing strict access controls
Misleading attackers to reveal their techniques
Creating complex passwords for all systems
What are the ethical considerations associated with deploying deception technologies?
Risk of harming legitimate users
Increased workload for IT staff
Higher costs for implementation
Legal implications of data capture
Which type of information can organizations gather from analyzing honeypot interactions?
Employee performance metrics
Trends in attacker behavior and tactics
Customer satisfaction data
Hardware inventory
What is one potential drawback of using honeypots in a security strategy?
They can provide valuable data on attacks.
They may require significant resources to manage.
They are easy to set up and maintain.
They are always effective against all types of attacks.
What can trigger an alert when a honeytoken is accessed?
An employee opening a legitimate file
A scheduled software update
Unauthorized access to fake credentials
Normal system maintenance
In which scenario would a honeypot be most effective?
Protecting against natural disasters
Detecting insider threats
Luring external attackers to study their methods
Monitoring employee productivity
What is a significant benefit of utilizing honeytokens in an organization?
They eliminate the need for user training.
They provide a way to detect unauthorized access.
They enhance physical security measures.
They can replace traditional firewalls.
What distinguishes a honeypot from a standard network device?
Honeypots are designed to provide real services.
Honeypots collect data on unauthorized access attempts.
Honeypots require complex user authentication.
Honeypots cannot be monitored remotely.
What is the primary purpose of a honeytoken within an organization?
To authenticate user identities
To monitor employee productivity
To detect unauthorized access through fake data
To enhance backup solutions
Which of the following is the first step in conducting a Gap Analysis?
Create an action plan
Define the target state
Assess the current state
Identify risks
A company conducts a Gap Analysis and finds that its password policies are not aligned with industry standards. What should be the next step?
Patch outdated software
Conduct a vulnerability scan
Update the password policy
Remove all administrator accounts
Why is monitoring and reviewing the effectiveness of solutions important after completing a Gap Analysis?
To identify potential internal threats
To ensure gaps do not reoccur
To prevent data breaches
To lower the cost of compliance
How does Gap Analysis contribute to risk management?
It reduces the need for encryption
It ensures data is always available
It identifies vulnerabilities and compliance issues
It automatically patches security flaws
The core principle of the Zero Trust model is:
Trust but verify
Implicit trust of internal networks
Never trust, always verify
Minimal encryption
Zero Trust applies to which of the following areas of cybersecurity?
Network security only
User identity only
All areas: users, devices, networks, applications, and data
Physical security only
Which of the following technologies would best support a Zero Trust model?
Anti-virus software
Firewall
Multi-Factor Authentication (MFA)
Single-factor password authentication
What does Non-Repudiation ensure in a communication or transaction?
That sensitive information is accessed only by authorized individuals.
That information remains unaltered and accurate.
That both the sender of a message and the recipient cannot deny having sent or received the message.
That systems and data are accessible when needed.
What is a digital signature used for in the context of Non-Repudiation?
To verify the authenticity and integrity of a message or document.
To encrypt sensitive information.
To ensure systems and data are accessible when needed.
To create backups of important data.
How does non-repudiation support integrity?
By encrypting data
By using digital signatures and hashing mechanisms
By marking the time of actions
By verifying the sender's identity
What is the purpose of the AAA security concept?
To encrypt data
To provide a framework for controlling access to resources and tracking user activities
To ensure data availability
To prevent data breaches
Which of the following is a primary function of the AAA framework in cybersecurity?
Authentication of users
Data backup
Firewall configuration
System updates
Which of the following is a primary goal of the CIA triad?
To ensure data is encrypted
To ensure data is only accessible to authorized users
To ensure data is backed up regularly
To ensure data is shared widely
Which of the following is the best example of a loss of Availability?
Unauthorized access to sensitive data
Data being modified without permission
Denial of Service (DoS) attack on a web server
Sensitive data being encrypted using strong algorithms
What method can be used to ensure Availability in the event of a natural disaster?
Public-key cryptography
Offsite backups
Strong password policies
Integrity checks
