wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Domain 1 - Network Security

Total questions: 46

Worksheet time: 23mins

Name
Class
Date
1.

Which aspects of core security fall under the purview of confidentiality? Choose three (3) answers.

a)

Controlling accessibility

b)

Encryption

c)

Tracking data

d)

Strong authentication

e)

Strict control of permissions

2.

Which of the following are examples of levels of confidentiality utilized by organizations? Choose three answers.

a)

Nonconfidential

b)

Internal use only

c)

Top secret

d)

Public

e)

Privileged

3.

Match each of the following terms to their proper definitions.

a)

AVAILABILITY: keeps data secure from unauthorized access

INTEGRITY: keeps data accurate and valid.

CONFIDENTIALITY: keeps data accessible to those who need it.

b)

CONFIDENTIALITY: keeps data secure from unauthorized access

INTEGRITY: keeps data accurate and valid.

AVAILABILITY: keeps data accessible to those who need it.

c)

AVAILABILITY: keeps data secure from unauthorized access

CONFIDENTIALITY: keeps data accurate and valid.

INTEGRITY: keeps data accessible to those who need it.

4.

Which methods can ensure the integrity of information, such as the contents of an email? Choose two answers.

a)

Labels

b)

A digital signature

c)

A redundancy

d)

MFA

e)

Encryption

5.

The availability part of the CIA triangle ensures that data is protected from which circumstances? Choose three answers.

a)

Natural disaster

b)

Malware

c)

Equipment failure

d)

Theft

e)

Corporate mismanagement

6.

A RISK is the possibility of data being compromised. What word should replace RISK in order for the sentence to correct?

a)

Vulnerability

b)

Mitigation

c)

The word is correct in the sentence

d)

Threat

7.

What is a weakness in the CIA of data known as?

a)

Threat

b)

Risk

c)

Vulnerability

d)

Acceptance

8.

What does mitigating a risk mean?

a)

Lessening the impact of a risk

b)

Do nothing about it but acknowledge the risk.

c)

Sharing the risk burden

d)

Do nothing about it

9.

(BLANK) and (BLANK) should be used to control permissions.

a)

Passwords; verification

b)

Logins; accounts

c)

Groups; roles

d)

Users; management

10.

Increasing the amount of privileges for a given user (BLANK) a system’s attack surface.

a)

Exposes

b)

Protects

c)

Limits

d)

Increases

11.

Look at the following statement and choose whether the phrase, “Threat modeling” is correct or needs to be replaced: Threat modeling is the process of identifying threats and vulnerabilities and then defining preventative countermeasures.

a)

Threat analysis

b)

Attack modeling

c)

The statement is correct as it

d)

Attack analysis

12.

Which security concept involves applying multiple layers of security?

a)

Sandboxing

b)

Firewalls

c)

Preclusive defense

d)

Defense in depth

13.

Securing fences and gates with guards and using security cameras help secure which area of access control?

a)

Separation barrier

b)

External perimeter

c)

Virtual private network

d)

Internal perimeter

14.

Which security mechanism sits just inside the entry point of building?

a)

Zone of control

b)

Mantrap

c)

Trap door

d)

Entrapment zone

15.

For thumb drives and external drives, encryption through (BLANK) should be used to encrypt the drive

a)

Ciphertext

b)

MetaFrame

c)

OpenPGP

d)

BitLocker

16.

The idea of restricting both physical and file/server access to only those who need it is known as (BLANK)

a)

Access control

b)

Site security

c)

Social engineering

d)

Principle of least privilege

17.

Which are methods for securing smartphones? Choose three answers.

a)

Mobile device management software

b)

Tethering

c)

Biometrics

d)

Password/PIN protection

e)

Mobile hotspots

18.

Attackers use a (BLANK) to intercept and record what people type.

a)

Pastebin

b)

Keylogger

c)

Transient cookie

d)

Rootkit

19.

Which statements are true of mantraps? Choose two (2) answers.

a)

Mantraps employ physical controls such as barricades and bollards to prevent illegal entry.

b)

Mantraps protect against social engineering techniques such as phishing, vishing, and whaling.

c)

Mantraps are considered physical, psychological, and social deterrents from confidential areas within a building

d)

Mantraps are physicals controls that serve as a gateway from an unsecure part of a building to a secure part of a building

e)

Persons caught in a mantrap are often questioned by security guards of similar individuals

20.

Which social engineering technique do mantraps defend against?

a)

Whaling

b)

Spear phishing

c)

Tailgating

d)

Dumpster diving

e)

Impersonation

21.

Which of the following are examples of technical controls? Choose two (2) answers.

a)

Documentation

b)

Cmdlets

c)

Hashing algorithms

d)

Firewalls

e)

Inclusion detection systems

22.

A buffer overflow attack occurs when one attempts to fill a(n) (BLANK) field with a number outside the (BLANK) range.

a)

Integer, number

b)

Buffer, integer

c)

Integer, integer

d)

Buffer, number

23.

(BLANK) are self-replicating malicious code blocks that are capable of running without a carrier.

a)

Trojan horses

b)

Viruses

c)

Zero day attacks

d)

Worms

24.

A user calls a help desk and states that an antivirus program downloaded is not actually an antivirus program. What does the user have?

a)

Trojan horse

b)

Zero day attack

c)

Worm

d)

Virus

25.

Which of these describe common types of ransomware? Choose two (2) answers.

a)

Crackware

b)

Lockscreen

c)

Encryption

d)

Scareware

e)

Registry lock

26.

A user complains that newly installed software is displaying advertisements at the top of the screen. Which of the following has most likely been installed?

a)

Worm

b)

Virus

c)

Adware

d)

Spyware

27.

A rootkit is used to gain which kind of access to a computer without being detected?

a)

Executive

b)

Global

c)

Administrative

d)

Guest

28.

Which of the following describes a class of malware that creates hidden openings in the OS?

a)

Backdoor

b)

Trojan horse

c)

OpenPGP

d)

Directory traversal

29.

Which of the following malware types causes security breaches that have not yet been identified by credible sources?

a)

Zero day attack

b)

Polymorphica

c)

I’ma Hoax

d)

Logic bomb

30.

A (BLANK) network attack utilizes multiple machines to disrupt a network to the point where it can no longer function.

a)

DoS

b)

Botnet

c)

Zombie

d)

DDoS

31.

Which common attack method injects a fraudulent destination for an IP address?

a)

Replay attack

b)

 DNS poisoning

c)

 Cross-site scripting

 

d)

 SQL injection attack

32.

Which type of attack method is used to intercept data while it is being transferred?

a)

Back door attack

b)

Replay attack

 

c)

 Email bombing

d)

Man-in-the middle

33.

Which password policies help mitigate brute force attacks? Choose two (2) answers.

a)

Passwords expire after a set time

b)

Passwords are changed regularly  

c)

 

Passwords are stored in secure browsers

d)

Passwords are complex

e)

Passwords are longer than 16 characters

34.

Which three (3) scenarios are examples of MITB attacks?

a)

An attacker changes the browser settings on a device

An attacker redirects data being sent from a browser to a device of their choosing

An attacker uses a script to obtain the cookies and certificates stored on a browser

b)

An attacker changes the browser settings on a device

An attacker runs SQL statements to infiltrate and change the data in a webpage

An attacker redirects data being sent from a browser to a device of their choosing

c)

An attacker redirects data being sent from a browser to a device of their choosing

An attacker records a user’s keystrokes and uses the captured password to hack into the user’s browser

An attacker uses a script to obtain the cookies and certificates stored on a browser

d)

An attacker changes the browser settings on a device

An attacker redirects data being sent from a browser to a device of their choosing

An attacker uses a script to obtain the cookies and certificates stored on a browser

35.

What method do attackers use to inject malicious activity by targeting client-side scripts?

a)

SQL injection

b)

Cross-site scripting

c)

Man-in-the-middle attack

d)

Brute force attack

e)

Man-in-the-browser attack

36.

How do attackers manipulate information on servers by running SQL statements?

a)

Man-in-the-middle attack

b)

Brute force attack

       

c)

   Cross-site scripting

d)

SQL injection

      

e)

Man-in-the-browser attack

37.

What type of attack involves attackers attempting to guess the password of an account?

a)

Brute force attack

   

b)

Man-in-the-browser attack

c)

SQL injection

        

d)

Man-in-the-middle attack

e)

Cross-site scripting

38.

How do attackers intercept data transmission between two devices?

a)

Man-in-the-browser attack

b)

SQL injection

        

c)

Man-in-the-middle attack

d)

Cross-site scripting

e)

Brute force attack

        

39.

By sending a script to a website and obtaining privileges to modify webpages, attackers are conducting which type of attack?

a)

Man-in-the-middle attack

b)

Cross-site scripting

c)

Man-in-the-browser attack

d)

SQL injection

        

e)

Brute force attack

       

40.

Which 3 (three) are examples of social engineering?

a)

Phone calls asking for info

Student job shadowing

Emails asking for info

b)

Phishing websites

Phone calls asking for information

Emails asking for information

c)

Phishing websites

IRS office audit

Phone calls asking for information

d)

Phishing websites

IRS office audit

Emails asking for information

e)

IRS office audit

Student job shadowing

Emails asking for information

41.

Which three (3) statements are true of keylogging?

a)

While keylogging is often malicious, some users utilize keyloggers legitimately

The use of a keylogger is illegal and ownership of one can result in monetary fines

A keylogger is typically used to capture user credentials

b)

Keyloggers include hardware and software tools that capture keystrokes

While keylogging is often malicious, some users utilize keyloggers legitimately

A keylogger is typically used to capture user credentials

c)

Keyloggers include hardware and software tools that capture keystrokes

Surveillance techniques such as shoulder surfing are examples of keylogging

While keylogging is often malicious, some users utilize keyloggers legitimately

d)

Keyloggers include hardware and software tools that capture keystrokes

Surveillance techniques such as shoulder surfing are examples of keylogging

While keylogging is often malicious, some users utilize keyloggers legitimately

The use of a

e)

Keyloggers include hardware and software tools that capture keystrokes

Surveillance techniques such as shoulder surfing are examples of keylogging

The use of a keylogger is illegal and ownership of one can result in monetary fines

42.

Which three (3) scenarios are examples of the correct usage of a logic bomb?

a)

An attacker sets a logic bomb to detonate in a power grid  on the Western coast

An attacker sets a logic bomb to detonate on May 5, 2005 at 5 PM

An attacker sets a logic bomb to detonate on Christmas Eve

b)

An attacker sets a logic bomb to detonate in a power grid  on the Western coast

An attacker sets a logic bomb to detonate on May 5, 2005 at 5 PM

An attacker sets a logic bomb to detonate one month after they were fired from a company

c)

An attacker sets a logic bomb to detonate randomly across several machines

An attacker sets a logic bomb to detonate one month after they were fired from a company

An attacker sets a logic bomb to detonate on Christmas Eve

d)

An attacker sets a logic bomb to detonate randomly across several machines

An attacker sets a logic bomb to detonate in a power grid  on the Western coast

An attacker sets a logic bomb to detonate on May 5, 2005 at 5 PM

e)

An attacker sets a logic bomb to detonate on May 5, 2005 at 5 PM

An attacker sets a logic bomb to detonate one month after they were fired from a company

An attacker sets a logic bomb to detonate on Christmas Eve

43.

Which two (2) statements are true of setting up a full backup?

a)

Full backups are typically not performed every day

Full backups are set to occur automatically by default

b)

Full backups are typically not performed every day

Full backups connected to an external hard drive are less secure than those saved to a local drive)

c)

Full backups should not interfere with day-to-day operations

Full backups are set to occur automatically by default

d)

Full backups are typically not performed every day

Full backups should not interfere with day-to-day operations

e)

Full backups are typically performed every day

Full backups are set to occur automatically by default

44.

Under which two (2) circumstances do differential backups typically occur?

a)

Before an incremental backup

After an incremental backup

b)

Before an incremental backup

At the same time as a full backup

c)

After a full backup

After an incremental backup

d)

At the same time as a full backup

After a full backup

e)

Before a full backup

After an incremental backup

45.

As more backups take place from the last full or incremental backup, the size of the differential backup file (BLANK)

a)

decreases

b)

halves

c)

increases

d)

doubles

46.

A full restore of data that uses differential backups requires restoring the last full backup, as well as (BLANK) backup(s).

a)

The last differential

b)

All incrementals

c)

All differentials

d)

The first differential