wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Unit 3 - Part 3 Review

Total questions: 63

Worksheet time: 32mins

Name
Class
Date
1.

What is an example of a physical security control that channels people through a specific point while prohibiting vehicle access?

a)

Access Badge

b)

Fences and Signs

c)

Video Surveillance

d)

Access Control Vestibule

2.

How do access control vestibules enhance security?

a)

By providing weight sensors to detect hardware removal.

b)

By enforcing a "one scan, one entry" guideline.

c)

By incorporating motion recognition cameras.

d)

By allowing unrestricted access to restricted areas.

3.

What is the purpose of fences and signs as physical security controls?

a)

To eliminate blind spots in video surveillance.

b)

To channel people through a specific point.

c)

To provide weight sensors for hardware detection.

d)

To mark boundaries, control access, and prevent escape.

4.

What is a potential drawback of using signage as a physical security control?

a)

It deters all malicious users.

b)

It provides clear instructions for authorized personnel.

c)

It may attract attention to restricted areas for malicious users.

d)

It enhances the effectiveness of security guards.

5.

What is the primary purpose of video surveillance in physical security?

a)

To channel people through a specific point.

b)

To provide weight sensors for hardware detection.

c)

To enforce a "one scan, one entry" guideline.

d)

To see what is happening within a facility and eliminate blind spots.

6.

What is the purpose of a security guard as a physical security control?

a)

To enforce access control policies and manage user identities.

b)

To provide weight sensors for hardware detection.

c)

To monitor and track progress in closing identified security gaps.

d)

To allow or disallow people through a security checkpoint and provide authentication.

7.

How does an access badge contribute to physical security?

a)

By eliminating blind spots in video surveillance.

b)

By providing weight sensors for hardware detection.

c)

By distinguishing personnel and correlating logs between physical and digital worlds.

d)

By providing access to restricted areas without authentication.

8.

What is the primary purpose of proper internal and external lighting as a physical security control?

a)

To enhance the effectiveness of security guards.

b)

To provide weight sensors for hardware detection.

c)

To eliminate blind spots in video surveillance.

d)

To deter intruders and enhance visibility for monitoring activities.

9.

What is an example of unauthorized access in physical attacks?

a)

Intercepting communication by tapping into network cables.

b)

Manipulating individuals into divulging confidential information.

c)

Searching through discarded materials to find sensitive information.

d)

Gaining physical access to a system or facility without permission.

10.

What is hardware tampering in physical attacks?

a)

Listening in on communication by tapping into network cables.

b)

Manipulating computer hardware to compromise its integrity or functionality.

c)

Searching through discarded materials to find sensitive information.

d)

Manipulating individuals into divulging confidential information.

11.

What is eavesdropping in physical attacks?

a)

Manipulating computer hardware to compromise its integrity or functionality.

b)

Gaining physical access to a system or facility without permission.

c)

Listening in on or intercepting communication by tapping into network cables or devices.

d)

Searching through discarded materials to find sensitive information.

12.

What is dumpster diving in physical attacks?

a)

Gaining physical access to a system or facility without permission.

b)

Manipulating computer hardware to compromise its integrity or functionality.

c)

Searching through discarded materials to find sensitive information.

d)

Manipulating individuals into divulging confidential information.

13.

What is the goal of social engineering attacks in physical attacks?

a)

To gain physical access to a system or facility.

b)

To manipulate computer hardware to compromise its integrity.

c)

To intercept communication by tapping into network cables.

d)

To manipulate individuals into divulging confidential information or performing actions that compromise security.

14.

What type of attack involves exploiting electromagnetic signals to interfere with electronic systems?

a)

Electromagnetic Attacks

b)

Power Attacks

c)

Environmental Attacks

d)

RFID Cloning Attacks

15.

How can brute force attacks be mitigated?

a)

By blocking accounts after a defined number of incorrect password attempts.

b)

By encrypting communication channels.

c)

By using RFID cards with other authentication measures.

d)

By increasing the temperature and humidity levels in server rooms.

16.

What is RFID cloning in physical attacks?

a)

Gaining physical access to a system or facility without permission.

b)

Manipulating computer hardware to compromise its integrity or functionality.

c)

Exploiting vulnerabilities in the power supply to disrupt or compromise systems.

d)

Copying the data stored on an RFID card to create a duplicate card for unauthorized access.

17.

What do environmental attacks target in physical attacks?

a)

Manipulating communication channels.

b)

Manipulating computer hardware.

c)

Manipulating physical conditions of a system.

d)

Manipulating individuals into divulging confidential information.

18.

What is an example of an environmental attack?

a)

Tampering with temperature and humidity levels to disrupt operations.

b)

Manipulating computer hardware components.

c)

Intercepting communication by tapping into network cables.

d)

Breaking into a data center to gain unauthorized access to server rooms.

19.

What does Mobile Device Management (MDM) involve?

a)

Managing desktop computers

b)

Administering mobile devices like smartphones and tablets

c)

Setting up Wi-Fi routers

d)

Monitoring server performance

20.

Which deployment model allows employees to use their personal devices for work purposes?

a)

Bring Your Own Device

b)

Corporate-Owned, Personally Enabled

c)

Choose Your Own Device

d)

Company-Owned Device

21.

In the Corporate-Owned, Personally Enabled (COPE) deployment model, who maintains control over the device and its security?

a)

The employee

b)

The IT department

c)

The device manufacturer

d)

The HR department

22.

What is the purpose of the Choose Your Own Device deployment model?

a)

Employees use their personal devices for work purposes

b)

Employees must use company-owned devices

c)

Employees choose their devices from a list provided by the company

d)

Employees must use a specific device model chosen by the company

23.

Which connection method is crucial for remote work and on-the-go connectivity, utilizing cellular data networks?

a)

Bluetooth

b)

Wi-Fi

c)

Ethernet

d)

Cellular

24.

Where is Wi-Fi connection commonly used?

a)

Remote areas

b)

Corporate offices

c)

Underground tunnels

d)

Airplanes

25.

Which of the following is NOT a component of a comprehensive mobile solution?

a)

A. Deployment models

b)

B. Connection methods

c)

C. Inventory management

d)

D. Security management

26.

What unique challenges do deployment models and connection methods address in a corporate environment?

a)

A. Managing desktop computers

b)

B. Inventory management

c)

C. Connectivity and security of mobile devices

d)

D. Server performance monitoring

27.

How do deployment models and connection methods work together in a mobile solution?

a)

They address different aspects of mobile device management

b)

Deployment models dictate which connection methods can be used

c)

They have no relation

d)

Connection methods determine the deployment model

28.

What is Bluetooth commonly used for?

a)

Long-range communication between devices

b)

File sharing and connecting peripherals

c)

Connecting to cellular networks

d)

Connecting to Wi-Fi networks

29.

What are cryptographic vulnerabilities primarily concerned with?

a)

Weaknesses in network configurations

b)

Flaws in supply chain management

c)

Security risks associated with mobile devices

d)

Weaknesses in the design, implementation, or use of cryptographic systems

30.

What is a common vulnerability associated with key management in cryptographic systems?

a)

Misconfiguration of firewall rules

b)

Key generation weaknesses

c)

Default settings in software

d)

Insecure random number generation

31.

What is the term used to describe the installation of applications on a mobile device from unofficial sources?

a)

Rooting

b)

Jailbreaking

c)

Side-loading

d)

Misconfiguration

32.

What is the risk associated with side-loading applications on mobile devices?

a)

Exposure to zero-day vulnerabilities

b)

Installation of malware or spyware

c)

Bypassing built-in security features

d)

Compromising the integrity of the device's hardware

33.

What is the process called when users remove software restrictions on their mobile devices to gain elevated privileges?

a)

Rooting

b)

Jailbreaking

c)

Side-loading

d)

Misconfiguration

34.

What is the primary concern with rooting or jailbreaking mobile devices?

a)

Exposure to zero-day vulnerabilities

b)

Installation of unauthorized apps

c)

Bypassing built-in security features

d)

Compromising cryptographic systems

35.

What is a characteristic of zero-day vulnerabilities?

a)

Known to the software or hardware vendor

b)

Limited time window between discovery and patch release

c)

Existence of pre-existing security measures or signatures

d)

Exploited by attackers using traditional security mechanisms

36.

What is a common characteristic of misconfiguration vulnerabilities?

a)

Exploited through side-channel attacks

b)

Root cause is related to cryptographic systems

c)

Result from errors or oversights in configuration

d)

Occur primarily in mobile devices

37.

What is a potential risk associated with misconfiguration vulnerabilities?

a)

Exposure to zero-day vulnerabilities

b)

Installation of malware or spyware

c)

Unauthorized access due to weak credentials

d)

Compromise of data confidentiality and integrity

38.

How can organizations mitigate the impact of zero-day vulnerabilities?

a)

Regularly update and patch software and systems

b)

Implement network segmentation

c)

Utilize intrusion detection systems

d)

All of the above

39.

What are firmware vulnerabilities?

a)

Security flaws in hardware components

b)

Weaknesses in virtualization technologies

c)

Security flaws in embedded software

d)

Vulnerabilities specific to cloud computing

40.

What is a potential consequence of exploiting firmware vulnerabilities?

a)

Unauthorized access to the host system

b)

Resource reuse between virtual machines

c)

Loss of visibility in cloud infrastructure

d)

Legal consequences due to compliance failure

41.

When does hardware reach its end-of-life (EOL)?

a)

When it lacks modern security features

b)

When it becomes incompatible with legacy hardware

c)

When the manufacturer stops providing support and updates

d)

When it is decommissioned properly

42.

What is a common vulnerability associated with legacy hardware?

a)

Insufficient network security

b)

Inadequate identity management

c)

Mismanagement of credentials

d)

Lack of modern security features

43.

How can organizations mitigate hardware vulnerabilities?

a)

Regularly apply patches and updates to firmware

b)

Implement strong isolation mechanisms between virtual machines

c)

Encrypt data at rest and in transit

d)

Use Security Information and Event Management (SIEM) systems

44.

What is a characteristic of VM escape vulnerability?

a)

Unauthorized access to the host system from a virtual machine

b)

Insecure handling of virtualized resources

c)

Weaknesses in virtualization technologies

d)

Loss of visibility in cloud infrastructure

45.

How can resource reuse vulnerabilities be mitigated?

a)

Conducting regular compliance assessments

b)

Regularly updating and patching the hypervisor

c)

Using Security Information and Event Management (SIEM) systems

d)

Implementing strong isolation mechanisms between VMs

46.

What is a cloud-specific vulnerability?

a)

Insufficient network security

b)

Lack of modern security features in legacy hardware

c)

Inadequate identity, credential, and access management

d)

End-of-life issues in hardware components

47.

How can organizations address inadequate network security in cloud environments?

a)

Implementing network segmentation

b)

Regularly updating and patching APIs

c)

Proper disposal or destruction of decommissioned hardware

d)

Using Security Information and Event Management (SIEM) systems

48.

What is a potential consequence of misconfigurations in cloud environments?

a)

Loss of customer trust

b)

Unauthorized access to the host system

c)

Resource reuse between virtual machines

d)

Insufficient control over security measures

49.

What is a buffer overflow vulnerability?

a)

When a user gains unauthorized access to higher-level privileges.

b)

Errors in the configuration of security settings.

c)

When a program writes more data to a buffer than it can handle, leading to the overflow of adjacent memory.

d)

Use of outdated communication protocols and services.

50.

Which type of vulnerability occurs when a user or process gains unauthorized access to higher-level privileges?

a)

Privilege Escalation

b)

Denial-of-Service (DoS) Attack

c)

Buffer Overflow

d)

SQL Injection

51.

What is the primary purpose of a Denial-of-Service (DoS) attack?

a)

To gain unauthorized access to sensitive data.

b)

To execute arbitrary code on a system.

c)

To overload a system with traffic, making it slow or unresponsive.

d)

To intercept data in transit.

52.

What is the term used to describe security flaws that are unknown to the software vendor and have no available patch?

a)

Zero-Day Vulnerabilities

b)

Unpatched Software

c)

Security Misconfigurations

d)

Outdated Protocols

53.

Which type of attack occurs when a user injects commands or code into a web server to execute?

a)

Cross-site Scripting (XSS)

b)

Command Injection

c)

SQL Injection

d)

Denial-of-Service (DoS) Attack

54.

SQL stands for:

a)

Secure Query Language

b)

Structured Query Language

c)

Server Query Language

d)

System Query Language

55.

What is the primary purpose of Cross-site Scripting (XSS)?

a)

To gain unauthorized access to sensitive data.

b)

To execute arbitrary code on a system.

c)

To bypass access controls and impersonate users.

d)

To overload a system with traffic, making it slow or unresponsive.

56.

Which technology is subject to injection attacks when used for structuring data exchanged on the web?

a)

LDAP

b)

XML

c)

DLL

d)

SQL

57.

What is the primary purpose of Group Policy in operating system security?

a)

Monitoring user behavior

b)

Providing encryption for data transfers

c)

Enforcing security settings and configurations

d)

Detecting changes to files and file systems

58.

Which operating system security component provides mandatory access controls?

a)

Group Policy

b)

File Integrity Monitoring

c)

SELinux

d)

Data Loss Prevention

59.

What is the main function of File Integrity Monitoring?

a)

Preventing unauthorized access to the network

b)

Monitoring user activities

c)

Detecting changes to files and file systems

d)

Controlling network access

60.

Which security measure is focused on preventing unauthorized access, sharing, or leakage of sensitive data?

a)

Network Access Control (NAC)

b)

Endpoint Detection and Response (EDR)

c)

Data Loss Prevention (DLP)

d)

User Behavior Analytics (UBA)

61.

What does Network Access Control (NAC) regulate and restrict?

a)

User access to files

b)

Software installation

c)

Access to the network based on predefined policies

d)

Endpoint activities

62.

Which security solution focuses on detecting and responding to security incidents at the endpoint level?

a)

User Behavior Analytics (UBA)

b)

Endpoint Detection and Response (EDR)

c)

File Integrity Monitoring

d)

Network Access Control (NAC)

63.

What is the primary goal of User Behavior Analytics (UBA)?

a)

Analyzing patterns of user behavior to identify security threats

b)

Regulating network access

c)

Preventing data loss

d)

Monitoring changes to files and file systems