wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CSF - Chapter 2 2024

Total questions: 50

Worksheet time: 2hrs 39mins

Name
Class
Date
1.

What name is given to a storage device connected to a network?

a)

DAS

b)

NAS

c)

Cloud

d)

RAID

2.

What is a method of sending information from one device to another using removable media?

a)

wireless

b)

infrared

c)

sneaker net

d)

wired

3.

What are two common hash functions? (Choose two.)

a)

MD5

b)

Blowfish

c)

RC4

d)

ECC

e)

SHA

4.

For the purpose of authentication, what three methods are used to verify identity? (Choose three.)

a)

something you have

b)

something you know

c)

something you are

d)

something you do

5.

What type of cybersecurity laws protect you from an organization that might want to share your sensitive data?

a)

confidentiality

b)

privacy

c)

nonrepudiation

d)

authentication

6.

What service determines which resources a user can access along with the operations that a user can perform?

a)

authentication

b)

biometric

c)

token

d)

authorization

7.

What are the three foundational principles of the cybersecurity domain? (Choose three.)

a)

integrity

b)

availability

c)

security

d)

confidentiality

e)

encryption

8.

What three methods help to ensure system availability? (Choose three.)

a)

up-to-date operating systems

b)

equipment maintenance

c)

system resiliency

d)

system backups

e)

integrity checking

9.

What is a secure virtual network called that uses the public network?

a)

NAC

b)

IPS

c)

VPN

d)

IDS

10.

What name is given to any changes to the original data such as users manually modifying data, programs processing and changing data, and equipment failures?

a)

integrity

b)

backup

c)

deletion

d)

modification

11.

What are two methods that ensure confidentiality? (Choose two.)

a)

availability

b)

authentication

c)

encryption

d)

authorization

e)

nonrepudiation

12.

What three design principles help to ensure high availability? (Choose three.)

a)

eliminate single points of failure

b)

check for data consistency

c)

detect failures as they occur

d)

use encryption

e)

provide for reliable crossover

13.

What is identified by the first dimension of the cybersecurity cube?

a)

safeguards

b)

knowledge

c)

goals

d)

tools

14.

What are three access control security services? (Choose three.)

a)

authorization

b)

availability

c)

access

d)

accounting

e)

authentication

15.

What three tasks are accomplished by a comprehensive security policy? (Choose three.)

a)

sets rules for expected behavior

b)

gives security staff the backing of management

c)

useful for management

d)

defines legal consequences of violations

e)

is not legally binding

16.

What are three types of sensitive information? (Choose three.)

a)

PII

b)

published

c)

declassified

d)

business

e)

classified

17.

What mechanism can organizations use to prevent accidental changes by authorized users?

a)

backups

b)

encryption

c)

SHA-1

d)

version control

18.

Which two methods help to ensure data integrity? (Choose two.)

a)

data consistency checks

b)

repudiation

c)

availability

d)

hashing

e)

privacy

19.

What principle prevents the disclosure of information to unauthorized people, resources, and processes?

a)

confidentiality

b)

accounting

c)

integrity

d)

nonrepudiation

20.

What are the three states of data? (Choose three.)

a)

in-process

b)

at rest

c)

encrypted

d)

suspended

e)

in-transit

21.

What is a secure virtual network called that uses the public network?

(a)  

22.

What is a method of sending information from one device to another using removable media?

(a)  

23.

Write down 1 of the 3 foundational principles of the cybersecurity domain.

(a)  

24.

 What are the foundational principles identified in the first dimension of the Cybersecurity Cube?

a)

Authentication, Authorization, and Accounting (AAA)

b)

Confidentiality, Integrity, and Availability (CIA) 

c)

Encryption, Decryption, and Hashing 

d)

Prevention, Detection, and Response (PDR) 

25.

 What does the second dimension of the Cybersecurity Cube focus on?

a)

Protecting network infrastructure

b)

Protecting physical security

c)

Protecting the three principles of information security

d)

Protecting the three states of data

26.

 What are the three possible states of data in cyberspace, as mentioned in the module? 

a)

Data in storage, Data at risk, Data in process

b)

Data at rest, Data in motion, Data in use

c)

Data in transit, Data at rest, Data in process

d)

Data encrypted, Data decrypted, Data hashed

27.

 What does the third dimension of the Cybersecurity Cube define?

a)

The goals of cybersecurity

b)

The states of data in cyberspace

c)

The skills and discipline for protection

d)

The technologies, devices, and products used for protection 

28.

 What does the text(Chapter 2.1) emphasize as necessary in addition to technological tools for cybersecurity professionals to defeat cyber criminals?

a)

Strong physical security

b)

A legal background

c)

Policies, procedures, and guidelines

d)

Advanced encryption algorithms 

29.

Which of the following is NOT one of the three principles of information security in the first dimension of the Cybersecurity Cube?

a)

Confidentiality

b)

Integrity 

c)

Availability

d)

Authentication

30.

Which of the following is considered sensitive information? 

a)

Publicly available names and telephone numbers

b)

Personal information (PII)

c)

Data protected from unauthorized access

d)

All of the above 

31.

What does the AAA represent(in the correct order) in the context of access control and security services?

(a)  

32.

What does the 3 "A"s in AAA represent in the context of access control and security services? 

a)

Authentication, Authorization, Accounting

b)

Authorization, Accounting, Authentication

c)

Accounting, Authorization, Authentication

d)

Authorization, Authentication, Accounting

33.

What does the term "checksum" refer to in the context of integrity checks?

a)

A snapshot of data at an instant in time

b)

A complex mathematical algorithm 

c)

A hash function 

d)

A value that verifies the integrity of files or strings of characters

34.

Which statements is TRUE about "checksum" in the context of integrity checks?

a)

A checksum is one example of a hash function.

b)

A checksum verifies the integrity of files, or strings of characters, before and after they transfer from one device to another across a local network or the Internet.

c)

Checksums simply convert each piece of information to a value and sum the total.

d)

To test the data integrity, a receiving system just repeats the process. If the two sums are equal, the data is valid. If they are not equal, a change occurred somewhere along the line.

35.

Which of the following is an example of direct-attached storage?

a)

Network Attached Storage (NAS) 

b)

Redundant Array of Independent Disks (RAID) 

c)

Cloud storage

d)

USB flash drive

36.

Give an example of direct-attached storage.

(a)  

37.

What does RAID stand for in the context of data storage? 

a)

Random Access Integrated Drive

b)

Redundant Array of Independent Disks

c)

Remote Access and Intrusion Detection

d)

Resilient Architecture for Integrated Data 

38.

What is a unique challenge of network storage systems, such as RAID, SAN, and NAS? 

a)

Limited capacity

b)

Limited performance

c)

Complexity in configuration and management

d)

Low data redundancy 

39.

What does "sneaker net" refer to in the context of data transmission? 

a)

A network based storage system

b)

Physically moving data using removable media

c)

A high-speed interface for network storage

d)

Transmitting data using radio waves 

40.

What is one of the challenges in protecting data during the processing stage?

a)

Limited data corruption during output

b)

Inoperable system sensors during input

c)

Difficulty in data transmission

d)

Adverse impact of invalid data modification 

41.

Which of the following is a hardware-based technology safeguard? 

a)

Network access control (NAC)

b)

Intrusion Prevention System (IPS)

c)

Virtual Private Network (VPN)

d)

Content filtering services 

42.

What is a characteristic of a Virtual Private Network (VPN)?

a)

It uses public networks for secure communication.

b)

It is used for content filtering services.

c)

It requires a set of checks before allowing a device to connect to a network.

d)

It is a dedicated intrusion detection system. 

43.

What is the purpose of a security policy in an organization? 

a)

To implement hardware-based safeguards

b)

To ensure consistency in system operations

c)

To detect signs of attacks on a network

d)

To control access and transmission of objectionable content 

44.

What are the tasks accomplished by a comprehensive security policy? 

a)

Identifying and authenticating users

b)

It sets the rules for expected behavior.

c)

It ensures consistency in system operations, software and hardware acquisition and use, and maintenance.

d)

It defines the legal consequences of violations.

e)

It gives security staff the backing of management.

45.

What does an Acceptable Use Policy (AUP) typically include?

a)

Identification and authentication policies

b)

Password policies

c)

Remote access policies

d)

Rules about what users can and cannot do on the network 

46.

What is the purpose of the ISO/IEC 27000 cybersecurity model?

a)

To provide a framework for network engineers

b)

To guide information security management

c)

To define the layers of the OSI model

d)

To specify hardware-based safeguards 

47.

How does the ISO/IEC 27000 cybersecurity model differ from the OSI model?

a)

It uses layers to describe security categories.

b)

It is a hierarchical relationship model.

c)

It uses domains to describe security categories.

d)

It defines the structure of network protocols. 

48.

What do the ISO 27001 control objectives serve as for an organization? 

a)

A checklist for implementing information security

b)

A framework for network configuration

c)

A model for hardware-based safeguards

d)

D. A guideline for cybersecurity audits 

49.

What is the purpose of a Statement of Applicability (SOA) in the context of ISO 27001?

a)

To define control objectives for an organization

b)

To determine which control objectives are applicable to the organization

c)

To provide technical direction for implementing controls

d)

To specify the structure of network protocols 

50.

How do organizations tailor the use of control objectives and controls in the ISO 27000 model? 

a)

By applying all control objectives universally

b)

By prioritizing confidentiality over integrity and availability

c)

By aligning with the organization's priorities regarding confidentiality, integrity, and availability

d)

By relying on hardware-based safeguards