NEW
Font size
WorksheetsTeach Cyber Mod 1.2 Risk Adversity Trust
Total questions: 29
Worksheet time: 15mins
Which statement describes why information assets must be identified for cybersecurity purposes?
Because you cannot protect what you have not identified
Because you should only protect what you have identified
Because you can only identify some information assets
Because you should only identify those information assets that are the most important
Which statement describes the purpose of a data classification system for cybersecurity?
To ensure filenames are compliant with the naming policy rules
To identify information assets and protect them from a loss of confidentiality, integrity and availability
To describe all possible vulnerabilities in the system
To initiate a threat assessment protocol
Inappropriate file access to, or disclosure of, protectively marked information, whether by an adversary or accidentally, is a loss of:
Availability
Confidentiality
Integrity
Availability and Confidentiality
User error resulting in the access to, modification of, and disclosure confidential information assets represents a loss of:
Confidentiality
Confidentiality and Integrity
Availability and Integrity
Availability
What is the term used to describe ensuring that authorized parties are able to access the information when it is needed?
Confidentiality
Integrity
Availability
Asset identification
Which term refers to a circumstance or event with the potential to have an adverse effect on organizational operations?
Threat
Vulnerability
Attack
Exploit
Which term refers to a weakness in an information system, system security procedures, internal controls, or implementation?
Threat
Vulnerability
Attack
Exploit
Which term refers to an attempt that exploits a weakness and compromises system integrity, availability, or confidentiality?
Threat
Vulnerability
Attack
Exploit
Fire, flood, or an adverse weather event impacting the security of information assets is known as a:
Threat
Bug
Attack
Exploit
A software bug that can cause a buffer overflow in a computer program resulting in a loss of confidentiality, integrity, or availability is known as a:
Threat
Vulnerability
Attack
Exploit
Human error resulting in a loss of confidentiality, integrity, or availability to an information resource is known as a:
Threat
Vulnerability
Attack
Exploit
Nation-state sponsored espionage activity is an example of:
Threat
Vulnerability
Attack
Exploit
Which term refers to an individual, group, organization, or government that conducts or has the intent to conduct detrimental activities?
Threat
Vulnerability
Adversary
Exploit
Ransomware attacks such as WannaCry that lock files until a ransom is paid compromises:
Confidentiality
Integrity
Availability
Integrity and Confidentiality
The process of granting access to information technology (IT) system resources (including files) only to authorized users is a primary control for:
Identification
Availability
Confidentiality
Integrity
A firewall is an example of a security control providing:
Identification
Authentication
Access Control
Protection
The comparison of cryptographic file hashes can be used as a control for:
Availability
Confidentiality
Integrity
Confidentiality and Availability
Using cryptographic hashes (especially for passwords) can be used as a control for:
Availability
Confidentiality
Integrity
Confidentiality and Availability
What essential steps are needed to assure confidentiality of data?
Prevention
Detection
Response mechanisms
All of the above
Requiring a password to log onto a system is a form of:
Identification
Authentication
Authorization
All of the above
Requiring a username to log onto a system is a form of:
Identification
Authentication
Authorization
All of the above
While the purpose of password complexity rules is to improve security, which statement describes a concern about the usefulness of this security measure?
Password complexity rules make it easy for brute force attacks.
Longer passwords ensure security because they cannot be cracked.
Some people may view security protocols as impediments to productivity.
Computers cannot use file hashes on complex passwords.
A complex system has multiple components in it. System security is a characteristic of a system that has:
Each system component individually secured
The interactions of the components are secure
Software and hardware that is secure
All combination of all of the above
True or false? Cybersecurity is a “hard problem” because security is only as strong as the weakest link and is limited to human actors.
True
False
True or false? Cybersecurity is a “hard problem” because cyberspace is large, interconnected, and complex.
True
False
True or false? Cybersecurity is a “hard problem” because cybersecurity solutions can be inexpensive.
True
False
The process of identifying the risks to system security and determining the probability of occurrence, the resulting impact, and the additional safeguards that mitigate this impact is known as:
CIA Triad
Risk Assessment
Incident Response
Risk Matrix
True or False? Risk an essential aspect of cybersecurity because given the complexity of cybersystems, there are no limits to how much control can be exerted to protect those systems.
True
False
True or False? Risk an essential aspect of cybersecurity because risk is needed to understand the likelihood that a threat source will exploit a vulnerability, and the resulting damage if the attack is successful.
True
False
