Font size
WorksheetsCSF - Chapter 2 2024
Total questions: 50
Worksheet time: 2hrs 39mins
What name is given to a storage device connected to a network?
DAS
NAS
Cloud
RAID
What is a method of sending information from one device to another using removable media?
wireless
infrared
sneaker net
wired
What are two common hash functions? (Choose two.)
MD5
Blowfish
RC4
ECC
SHA
For the purpose of authentication, what three methods are used to verify identity? (Choose three.)
something you have
something you know
something you are
something you do
What type of cybersecurity laws protect you from an organization that might want to share your sensitive data?
confidentiality
privacy
nonrepudiation
authentication
What service determines which resources a user can access along with the operations that a user can perform?
authentication
biometric
token
authorization
What are the three foundational principles of the cybersecurity domain? (Choose three.)
integrity
availability
security
confidentiality
encryption
What three methods help to ensure system availability? (Choose three.)
up-to-date operating systems
equipment maintenance
system resiliency
system backups
integrity checking
What is a secure virtual network called that uses the public network?
NAC
IPS
VPN
IDS
What name is given to any changes to the original data such as users manually modifying data, programs processing and changing data, and equipment failures?
integrity
backup
deletion
modification
What are two methods that ensure confidentiality? (Choose two.)
availability
authentication
encryption
authorization
nonrepudiation
What three design principles help to ensure high availability? (Choose three.)
eliminate single points of failure
check for data consistency
detect failures as they occur
use encryption
provide for reliable crossover
What is identified by the first dimension of the cybersecurity cube?
safeguards
knowledge
goals
tools
What are three access control security services? (Choose three.)
authorization
availability
access
accounting
authentication
What three tasks are accomplished by a comprehensive security policy? (Choose three.)
sets rules for expected behavior
gives security staff the backing of management
useful for management
defines legal consequences of violations
is not legally binding
What are three types of sensitive information? (Choose three.)
PII
published
declassified
business
classified
What mechanism can organizations use to prevent accidental changes by authorized users?
backups
encryption
SHA-1
version control
Which two methods help to ensure data integrity? (Choose two.)
data consistency checks
repudiation
availability
hashing
privacy
What principle prevents the disclosure of information to unauthorized people, resources, and processes?
confidentiality
accounting
integrity
nonrepudiation
What are the three states of data? (Choose three.)
in-process
at rest
encrypted
suspended
in-transit
What is a secure virtual network called that uses the public network?
(a)
What is a method of sending information from one device to another using removable media?
(a)
Write down 1 of the 3 foundational principles of the cybersecurity domain.
(a)
What are the foundational principles identified in the first dimension of the Cybersecurity Cube?
Authentication, Authorization, and Accounting (AAA)
Confidentiality, Integrity, and Availability (CIA)
Encryption, Decryption, and Hashing
Prevention, Detection, and Response (PDR)
What does the second dimension of the Cybersecurity Cube focus on?
Protecting network infrastructure
Protecting physical security
Protecting the three principles of information security
Protecting the three states of data
What are the three possible states of data in cyberspace, as mentioned in the module?
Data in storage, Data at risk, Data in process
Data at rest, Data in motion, Data in use
Data in transit, Data at rest, Data in process
Data encrypted, Data decrypted, Data hashed
What does the third dimension of the Cybersecurity Cube define?
The goals of cybersecurity
The states of data in cyberspace
The skills and discipline for protection
The technologies, devices, and products used for protection
What does the text(Chapter 2.1) emphasize as necessary in addition to technological tools for cybersecurity professionals to defeat cyber criminals?
Strong physical security
A legal background
Policies, procedures, and guidelines
Advanced encryption algorithms
Which of the following is NOT one of the three principles of information security in the first dimension of the Cybersecurity Cube?
Confidentiality
Integrity
Availability
Authentication
Which of the following is considered sensitive information?
Publicly available names and telephone numbers
Personal information (PII)
Data protected from unauthorized access
All of the above
What does the AAA represent(in the correct order) in the context of access control and security services?
(a)
What does the 3 "A"s in AAA represent in the context of access control and security services?
Authentication, Authorization, Accounting
Authorization, Accounting, Authentication
Accounting, Authorization, Authentication
Authorization, Authentication, Accounting
What does the term "checksum" refer to in the context of integrity checks?
A snapshot of data at an instant in time
A complex mathematical algorithm
A hash function
A value that verifies the integrity of files or strings of characters
Which statements is TRUE about "checksum" in the context of integrity checks?
A checksum is one example of a hash function.
A checksum verifies the integrity of files, or strings of characters, before and after they transfer from one device to another across a local network or the Internet.
Checksums simply convert each piece of information to a value and sum the total.
To test the data integrity, a receiving system just repeats the process. If the two sums are equal, the data is valid. If they are not equal, a change occurred somewhere along the line.
Which of the following is an example of direct-attached storage?
Network Attached Storage (NAS)
Redundant Array of Independent Disks (RAID)
Cloud storage
USB flash drive
Give an example of direct-attached storage.
(a)
What does RAID stand for in the context of data storage?
Random Access Integrated Drive
Redundant Array of Independent Disks
Remote Access and Intrusion Detection
Resilient Architecture for Integrated Data
What is a unique challenge of network storage systems, such as RAID, SAN, and NAS?
Limited capacity
Limited performance
Complexity in configuration and management
Low data redundancy
What does "sneaker net" refer to in the context of data transmission?
A network based storage system
Physically moving data using removable media
A high-speed interface for network storage
Transmitting data using radio waves
What is one of the challenges in protecting data during the processing stage?
Limited data corruption during output
Inoperable system sensors during input
Difficulty in data transmission
Adverse impact of invalid data modification
Which of the following is a hardware-based technology safeguard?
Network access control (NAC)
Intrusion Prevention System (IPS)
Virtual Private Network (VPN)
Content filtering services
What is a characteristic of a Virtual Private Network (VPN)?
It uses public networks for secure communication.
It is used for content filtering services.
It requires a set of checks before allowing a device to connect to a network.
It is a dedicated intrusion detection system.
What is the purpose of a security policy in an organization?
To implement hardware-based safeguards
To ensure consistency in system operations
To detect signs of attacks on a network
To control access and transmission of objectionable content
What are the tasks accomplished by a comprehensive security policy?
Identifying and authenticating users
It sets the rules for expected behavior.
It ensures consistency in system operations, software and hardware acquisition and use, and maintenance.
It defines the legal consequences of violations.
It gives security staff the backing of management.
What does an Acceptable Use Policy (AUP) typically include?
Identification and authentication policies
Password policies
Remote access policies
Rules about what users can and cannot do on the network
What is the purpose of the ISO/IEC 27000 cybersecurity model?
To provide a framework for network engineers
To guide information security management
To define the layers of the OSI model
To specify hardware-based safeguards
How does the ISO/IEC 27000 cybersecurity model differ from the OSI model?
It uses layers to describe security categories.
It is a hierarchical relationship model.
It uses domains to describe security categories.
It defines the structure of network protocols.
What do the ISO 27001 control objectives serve as for an organization?
A checklist for implementing information security
A framework for network configuration
A model for hardware-based safeguards
D. A guideline for cybersecurity audits
What is the purpose of a Statement of Applicability (SOA) in the context of ISO 27001?
To define control objectives for an organization
To determine which control objectives are applicable to the organization
To provide technical direction for implementing controls
To specify the structure of network protocols
How do organizations tailor the use of control objectives and controls in the ISO 27000 model?
By applying all control objectives universally
By prioritizing confidentiality over integrity and availability
By aligning with the organization's priorities regarding confidentiality, integrity, and availability
By relying on hardware-based safeguards
