wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Teach Cyber Mod 1.2 Risk Adversity Trust

Total questions: 29

Worksheet time: 15mins

Name
Class
Date
1.

Which statement describes why information assets must be identified for cybersecurity purposes?

a)

Because you cannot protect what you have not identified

b)

Because you should only protect what you have identified

c)

Because you can only identify some information assets

d)

Because you should only identify those information assets that are the most important

2.

Which statement describes the purpose of a data classification system for cybersecurity?

a)

To ensure filenames are compliant with the naming policy rules

b)

To identify information assets and protect them from a loss of confidentiality, integrity and availability

c)

To describe all possible vulnerabilities in the system

d)

To initiate a threat assessment protocol

3.

Inappropriate file access to, or disclosure of, protectively marked information, whether by an adversary or accidentally, is a loss of:

a)

Availability

b)

Confidentiality

c)

Integrity

d)

Availability and Confidentiality

4.

User error resulting in the access to, modification of, and disclosure confidential information assets represents a loss of:

a)

Confidentiality

b)

Confidentiality and Integrity

c)

Availability and Integrity

d)

Availability

5.

What is the term used to describe ensuring that authorized parties are able to access the information when it is needed?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Asset identification

6.

Which term refers to a circumstance or event with the potential to have an adverse effect on organizational operations?

a)

Threat

b)

Vulnerability

c)

Attack

d)

Exploit

7.

Which term refers to a weakness in an information system, system security procedures, internal controls, or implementation?

a)

Threat

b)

Vulnerability

c)

Attack

d)

Exploit

8.

Which term refers to an attempt that exploits a weakness and compromises system integrity, availability, or confidentiality?

a)

Threat

b)

Vulnerability

c)

Attack

d)

Exploit

9.

Fire, flood, or an adverse weather event impacting the security of information assets is known as a:

a)

Threat

b)

Bug

c)

Attack

d)

Exploit

10.

A software bug that can cause a buffer overflow in a computer program resulting in a loss of confidentiality, integrity, or availability is known as a:

a)

Threat

b)

Vulnerability

c)

Attack

d)

Exploit

11.

Human error resulting in a loss of confidentiality, integrity, or availability to an information resource is known as a:

a)

Threat

b)

Vulnerability

c)

Attack

d)

Exploit

12.

Nation-state sponsored espionage activity is an example of:

a)

Threat

b)

Vulnerability

c)

Attack

d)

Exploit

13.

Which term refers to an individual, group, organization, or government that conducts or has the intent to conduct detrimental activities?

a)

Threat

b)

Vulnerability

c)

Adversary

d)

Exploit

14.

Ransomware attacks such as WannaCry that lock files until a ransom is paid compromises:

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Integrity and Confidentiality

15.

The process of granting access to information technology (IT) system resources (including files) only to authorized users is a primary control for:

a)

Identification

b)

Availability

c)

Confidentiality

d)

Integrity

16.

A firewall is an example of a security control providing:

a)

Identification

b)

Authentication

c)

Access Control

d)

Protection

17.

The comparison of cryptographic file hashes can be used as a control for:

a)

Availability

b)

Confidentiality

c)

Integrity

d)

Confidentiality and Availability

18.

Using cryptographic hashes (especially for passwords) can be used as a control for:

a)

Availability

b)

Confidentiality

c)

Integrity

d)

Confidentiality and Availability

19.

What essential steps are needed to assure confidentiality of data?

a)

Prevention

b)

Detection

c)

Response mechanisms

d)

All of the above

20.

Requiring a password to log onto a system is a form of:

a)

Identification

b)

Authentication

c)

Authorization

d)

All of the above

21.

Requiring a username to log onto a system is a form of:

a)

Identification

b)

Authentication

c)

Authorization

d)

All of the above

22.

While the purpose of password complexity rules is to improve security, which statement describes a concern about the usefulness of this security measure?

a)

Password complexity rules make it easy for brute force attacks.

b)

Longer passwords ensure security because they cannot be cracked.

c)

Some people may view security protocols as impediments to productivity.

d)

Computers cannot use file hashes on complex passwords.

23.

A complex system has multiple components in it. System security is a characteristic of a system that has:

a)

Each system component individually secured

b)

The interactions of the components are secure

c)

Software and hardware that is secure

d)

All combination of all of the above

24.

True or false? Cybersecurity is a “hard problem” because security is only as strong as the weakest link and is limited to human actors.

a)

True

b)

False

25.

True or false? Cybersecurity is a “hard problem” because cyberspace is large, interconnected, and complex.

a)

True

b)

False

26.

True or false? Cybersecurity is a “hard problem” because cybersecurity solutions can be inexpensive.

a)

True

b)

False

27.

The process of identifying the risks to system security and determining the probability of occurrence, the resulting impact, and the additional safeguards that mitigate this impact is known as:

a)

CIA Triad

b)

Risk Assessment

c)

Incident Response

d)

Risk Matrix

28.

True or False? Risk an essential aspect of cybersecurity because given the complexity of cybersystems, there are no limits to how much control can be exerted to protect those systems.

a)

True

b)

False

29.

True or False? Risk an essential aspect of cybersecurity because risk is needed to understand the likelihood that a threat source will exploit a vulnerability, and the resulting damage if the attack is successful.

a)

True

b)

False