Font size
WorksheetsCyber security revision for Jan 25 exam
Total questions: 60
Worksheet time: 53mins
Which of these is not a field in a Cyber Security Incident Report
Target of the incident
Incident category
Type of attacker
Name of the incident
Which of these is the most serious category of incident
Critical
Significant
Minor
Negligible
Anyone who commits a cyber crime by breaking national or international law
Cyber Terrorist
Scammer
Phisher
Cyber Criminal
Allowing information to pass to any person without permission
Unauthorised Access
Unauthorised Inspection
Unaithorised Modification
Unauthorised Disclosure
The first phase of the vulnerability management lifecycle
Verify
Assess
Discover
Remediate
Once a vulnerability is identified we have to take corrective action, this is known as
Fixing
Remediation
Monitoring
Assessing
Which of these is a valid type of privilege escalation?
Vertical
Positional
Subterranean
Global
Which of these is a possible motivation of an insider?
Public Good
Income Generation
Settle a score
Fraud
Which of these are programs that detect attempts at intrusion and take action to prevent them
IDS
NIDS
HIDS
IPS
The level of assurance that the data will be accessible to those who need it when they want it
Confidentiality
Availability
Integrity
Accuracy
What would be the main motivation of a hacktivist?
Public Good
Settle a score
Thrill
Income Generation
Someone who tries to cheat you by offering goods or opportunities to make money quickly is a (a)
Hacker
Phisher
Cyber Criminal
What does BYOD stand for?
Bring your own data
Buy your own device
Bring your old device
Bring your own device
Which group of asset does a router fall into?
Hardware
Software
Communications Equipment
Information and data
Which of these is a symmetric method of cryptography
Blowfish
El Gamal
RSA
DSA
The level of assurance which can be given as to the accuracy and trustworthiness of the data
Confidentiality
Integrity
Availability
Fixes issues and bugs within the software
Patch
Update
Adds new features and functionality to the software
Patch
Update
Which law makes it an offence to send malicious and offensive communications.
Data Protection Act
Computer Misuse Act
Communications Act
Equality Act
Reading data, information or systems documentation without permission of the appropriate owner is unauthorised (a)
People that try and acquire your personal information usually via email
Phisher
Scammer
White hat hacker
Vulnerability Broker
Attackers place a piece of malware on a group of computers to form a network under their control
Virus
Dictionary Attack
DDOS Attack
BotNet Attack
The use of sophisticated tools to collect information and indentify trends and patterns
Data Mining
Cyber enabled crime
Cyber dependent crime
Money Laundering
These are cyber security incidents that cause a world wide problem for individuals, organisations or states.
Loss Incident
Global Incident
Disruption Incident
Saftey Incident
IT specialists employed or contracted by system owners to methodically attempt to penetrate a computer system
Scammer
Phisher
Ethical Hacker
Hacktivist
The information commisioner is responsible for enforcing which law
Data Protection Act/GDPR
Regulation of investigatory powers act
Computer Misuse Act
Communications Act
A premeditated, attack against information in order to cause fear or intimidation in society.
Cyber Criminal
Cyber Terrorist
Hacktivist
Script Kiddie
This attacker is usually young, intelligent, IT expert
Hacktivist
Hacker
Scammer
Cyber Criminal
Detects unusual or suspicious activity on a specific device.
IPS
IDS
NIDS
HIDS
The act of exploiting a bug, design flaw to gain elevated access to resources.
Escalation of priviledges
Unauthorised Modification
Phishing
Hacking
Is allowing information to pass to any person or organisation without permission.
Unauthorised Disclosure
Unauthorised Modification
Unauthorised Inspection
Unauthorised Access
The use of sophisticated tools to identify trends and patterns in large data stores.
Hacking
Money Laundering
Phishing
Data Mining
On unsecure public Wi-Fi, attackers can insert themselves between a visitor's device and the network.
Phishing
Hacking
DOS
Man in the middle attack
Uses existing computer scripts or codes to hack into computers, lacking the expertise to write their own ...
(a)
What is the main motivation of a vulnerability broker
Financial Gain
Righting a perceived wrong
Thrill
Espionage
A form of malware that encrypts a victim's files. The attacker then demands money from the victim
Spyware
Worm
Ransomware
Trojan
This law makes it an offence to transmit text messages which are offensive
Regulation of investigatory powers act
Computer Misuse Act
Communication Act
Data Protection Act
Categorize assets into groups or business units, and assign a business value to the asset
Verify
Remediate
Prioritize Assets
Discover
Which one of the following is NOT a type of CyberSecurity Attack?
Worm
Ransomware
Spyware
Password Management
DDoS
The technology and process that is designed to protect networks and devices from attack, damage, or unauthorized access
Cyber Security
White Hat Hacker
Domain Name Server
All of the above
What are the motives behind cyber crime?
Demanding ransom
Propagating religious or political beliefs
Financial loss to the target
Information thefts and manipulating data
All of the above
Individuals with wide range of skills motivated by religious or political beliefs to create fear by large- scale disruption of computer networks
State sponsored hacker
Hactivist
Cyber terrorist
Black hat hacker
Which of these are examples of system vulnerabilities?
Environmental
Updated software
Firewall
Systems Attacks
Physical
Which of these are targets for cyber security threats?
People
Equipment
paperwork
car keys
Locked doors
The Computer Misuse Act 1990 covers what area of law?
Controls how date is used by organisations
Governs the use of covert surveillance
Unauthorised access to computer material
Sending malicous communication over the internet
Which of these are types of system vulnerabilities?
Zero day
Social engineering
Encryption
Staff training
Two-factor authentication
What is the correct term for the use of sophisticated tools, such as AI techniques and statistical tools to identify trends and patterns in large data stores?
Key logging
Data mining
Currency tumbling
Money laundering
Which of these is an example of personal data?
Botnet
Bank account details
Social media profile
eBooks
What is a Cookie?
A vulnerability that presents a danger to your computer
A type of Spyware that reports your internet activities
A form of storage used by the browser for backing up websites
A small text file stored on a computer for tracking/storing user activites
Some websites have “http://” extension while some have “https://”
What does the ‘s’ mean?
That the data entered on the website is secure and encrypted.
It’s a special website.
That it’s the latest version of the site.
Its being loaded in a simple format.
According to the pre-release materials, what was the first recommended step for Triangle Widgets after the cyber security course?
Implement new security measures immediately
Conduct a review of existing cyber security measures and controls
Run table top exercises
Contact external organisations
In the table top exercise scenario described in the pre-release, what type of breach was simulated?
A physical security breach
A malware attack
A compromised manager's password
A social engineering attack
Which of the following was NOT mentioned as data accessed by the hacker in the pre-release scenario?
Financial transaction records
Customer information
Employee information
Organisational data
According to the pre-release, what is the primary purpose of conducting table top exercises?
To create new security policies
To identify compromised passwords
To train new employees
To test procedures and familiarise staff with CISR creation
In the pre-release, the course emphasised that cyber security is:
Only important for large corporations
A global responsibility affecting everyone
Limited to individual companies
Only relevant to IT departments
In the pre-release, what document is specifically mentioned as being created during table top exercises?
Security Breach Report
Incident Management Plan
Cyber Security Incident Report (CISR)
Risk Assessment Document
In the pre-release, the cyber security course covered incident response basics that included all EXCEPT:
How to respond to incidents
Financial compensation procedures
Containing and eradicating incidents
Dealing with affected parties
In the pre-release, the name of the company is?
(a)
According to the pre-release, what type of information should be identified during the security review?
Only digital assets
Just company policies
Employee performance records
Assets, procedures, policies, and vulnerabilities
The pre-release materials suggest further research on all topics EXCEPT:
How to analyse risk and identify vulnerable assets
Social media security protocols
Impact of incidents beyond the company
Responses to different categories of incidents
