WorksheetsANTT
Total questions: 109
Worksheet time: 3615secs
What threat involves a hacker intercepting and altering messages between two parties to manipulate the conversation?
Man-in-the-middle
Phishing
SQL Injection
Spear-phishing
Which two actions can help prevent malware infections? (choose two)
Updating software regularly
Using strong, unique passwords
Disabling antivirus software
Opening suspicious email attachments
A CEO receives a fake email from their “IT department” asking to reset their password. This is an example of which type of attack?
DDoS
Phishing
SQL Injection
Social Engineering
A user notices unwanted pop-ups and advertisements while browsing. Which type of malware is likely responsible?
Adware
Trojan
Spyware
Ransomware
Which of the following are examples of malware? (Choose two)
Spyware
Trojan
Firewall
SSL
Keyloggers are mainly used for tracking and advertising purposes
True
False
A worm needs user interaction to spread to other devices
True
False
A company notices that an unknown user has been attempting to connect to their servers using brute-force methods. What type of threat is this?
Insider threat
Malware
Password attack
Zero-day exploit
In SSL/TLS certificates, which encryption algorithm is commonly used to verify the server’s identity?
3DES
AES
MD5
RSA
Which encryption algorithm is preferred for securing real-time video streaming due to its speed?
RSA
AES
Triple DES
SHA-256
Which hashing algorithm would be appropriate for ensuring data integrity in blockchain transactions?
SHA-256
SHA-3
AES
MD5
Which symmetric encryption algorithm uses a 128-bit block size and variable key lengths?
DES
Blowfish
AES
RSA
For securing IoT devices with limited processing power, which lightweight symmetric algorithm is often used?
ChaCha20
AES
RSA
3DES
Which type of attack involves overwhelming a server with requests to make it unavailable?
Phishing
Man-in-the-Middle
DoS (Denial of Service)
SQL Injection
What encryption method is often used to protect passwords stored in databases?
RSA
AES
DES
Hashing
What is a common use of the Nmap tool in security?
To break passwords
To scan networks for open ports and services
To monitor employee activity
To encrypt files
Which tool monitors network traffic for suspicious activity in real-time?
Firewall
Antivirus
Intrusion Detection System (IDS)
VPN
An antivirus software scans for and removes which type of the following threats?
Physical threats
Phishing attempts
Malware
Social engineering attacks
Which of the following are common goals of ransomware attacks? (Choose two)
To lock files for ransom
To monitor keystrokes
To gain political leverage
To delete important files permanently
Which tools can a hacker use to scan a network for open ports? (Choose two)
Wireshark
Nmap
Angry IP Scanner
VPN
An organization tracks and logs each entry into a data center. Reviewing these logs helps fulfill which security objective?
Availability
Encryption
Confidentiality
Non-repudiation
Which two tools or practices enhance data integrity?
Firewalls
Hash functions
Data backups
Digital signatures
A denial-of-service (DoS) attack mainly impacts which component of the CIA Triad?
Confidentiality
Availability
Accountability
Integrity
An online store asks for a customer’s fingerprint in addition to their password. What security measure is this?
Multi Factor Authentication
Two-step verification
Password policy
Biometric policy
An organization uses VLANs to separate network traffic between its sales and HR departments. This primarily serves to _______
Enhance network speed
Strengthen data confidentiality
Improve employee collaboration
Reduce data redundancy
Which of the following practices help prevent data breaches? (Choose two)
Using multi-factor authentication
Weak password policies
Monitoring for unusual network activity
Limiting access to sensitive data
Which two principles are most critical in a hospital’s electronic health record system?
Availability
Usability
Confidentiality
Authenticity
Which of these combinations best illustrates two-factor authentication?
Username and password
Password and security question
Password and a one-time code sent to a mobile device
Password and security
A retail chain faces frequent thefts and unauthorized access in its warehouse storage areas. Which two physical security solutions could help reduce these incidents? (Select two)
Installing CCTV cameras throughout the warehouse
Implementing multi-factor authentication for online store access
Using RFID-tagged access cards for entry control
Encrypting customer data
A company’s data center has biometric scanners and security guards in place to restrict access. What kind of security control is this?
Physical control
Administrative control
Logical control
Recovery control
An employee installs software that secretly records passwords entered on their device. What type of malware is this?
Virus
Worm
Keylogger
Ransomware
Ransomware is only found on Windows systems
True
False
Leaving software unpatched in a public network environment can result in what kind of vulnerability?
Zero-day vulnerability
Insider threat
Password attack
Social Engineering
What type of attack targets an SQL database using the input field of a user?
SQL Injection
Cross-site scripting
XML Injection
Buffer overflow
Storing passwords in plain text within a database is an example of a ___________
Physical security vulnerability
Secure configuration
Misconfiguration vulnerability
Social engineering
Which encryption algorithm was replaced by AES due to vulnerabilities?
RSA
DES
SHA-1
MD5
Which measure is most effective in preventing brute-force attacks on passwords?
Encryption
Rate limiting
Close unused ports
Increased bandwidth
Which encryption algorithm is commonly used to secure online transactions, such as credit card payments?
AES
RSA
MD5
DES
If a company wants to encrypt large volumes of data quickly without compromising security, which algorithm should they choose?
AES
RSA
SHA-256
ECC
Zero-day vulnerabilities are immediately exploitable weaknesses unknown to the software vendor.
True
False
A bank installs anti-malware software on all employee computers to prevent infection. What is the main purpose of this security measure?
To encrypt data
To enable faster internet speed
To bypass firewall restrictions
To detect and remove malicious software
In a Man-in-the-Middle attack, what is the attacker attempting to do?
Block all communications
Encrypt all data being transmitted
Intercept and potentially alter communications between two parties
Gain physical access to a device
Which of these would be considered a vulnerability rather than a threat?
Misconfigured firewall
Malware infection
Phishing email
Unauthorized insider
A hacktivist is a hacker who breaks into systems to expose information for political or social causes.
True
False
Phishing emails often use social engineering to trick users into revealing sensitive information.
True
False
Which type of hacker is known for exploiting security weaknesses to improve security systems?
White Hat
Black Hat
Script Kiddie
Hacktivist
Which technology enhances confidentiality when accessing a public Wi-Fi network?
Firewall
Antivirus software
VPN
Network switch
Which of the following best describes an SQL Injection attack?
Inserting malicious code into a database query
Injecting code into a website to alter its appearance
Stealing files from a compromised device
Stealing files from a compromised device
Tools like John the Ripper are used for password cracking by systematically guessing passwords.
True
False
What is the main goal of a security guard stationed at the entrance of a restricted area in a corporate building?
To assist with network setup
To monitor internet traffic
To block cyber attacks
To prevent unauthorized physical access
What is the main purpose of CCTV in physical security?
To deter and monitor unauthorized access
To record staff working hours
To increase power efficiency
To assist in network monitoring
A hospital wants to protect sensitive patient information stored in a physical records room. Which two measures should the hospital implement to secure the room? (Select two)
Implementing keycard access control
Using water sensors to detect leaks
Setting up firewall protection
Establishing password policies for digital systems
Which of the following actions can improve physical security at an office? (Choose two)
Locking doors after hours
Installing antivirus software
Using keycard access
Blocking certain websites
In a scenario where a company faces frequent power outages, which solution would help ensure continuous power to critical systems?
Security cameras
Uninterruptible Power Supply (UPS)
Access control systems
Badge system
An organization creates daily backups of its customer database to an offsite location. This measure primarily protects against ___________
Phishing attacks
Data loss due to hardware failure or natural disaster
Unauthorized access
Malware infections
Which two of the following are common internal threats to information security?
Phishing attacks
Insider threats
Human error
Natural disasters
Which of the following is a primary reason organizations require information security?
To ensure data privacy and protect resources
To avoid technological advancements
To reduce customer base
To eliminate competition
What is considered a critical element of information security that ensures only authorized users can access certain resources?
Authentication
Integrity
Confidentiality
Availability
What two elements support integrity in an online shopping platform’s payment system?
Data hashing
Open public access
Secure Socket Layer (SSL)
Limiting customer information
What are two effective ways to ensure data availability?
Firewalls
Redundant servers
Data encryption
Backup solutions
Confidentiality ensures that only authorized personnel can access sensitive data.
True
False
An organization uses VLANs to separate network traffic between its sales and HR departments. This primarily serves to __________
Enhance network speed
Strengthen data confidentiality
Improve employee collaboration
Reduce data redundancy
To prevent malware, an organization restricts employee access to only necessary data. Which principle is this?
Authentication
Availability
Encryption
Least Privilege
Which document outlines an organization’s strategy for dealing with security breaches?
Security Policy
Risk Assessment Report
Disaster Recovery Plan
User Manual
A company implements digital certificates for authenticating its servers to users. This helps achieve which security goal?
Confidentiality
Authentication
Integrity
Availability
What are two primary methods used to deliver ransomware?
Phishing emails
Software vulnerabilities
Pop-up ads
Hardware issues
Which type of malware encrypts files on a computer and demands payment to decrypt them?
Adware
Spyware
Worm
Ransomware
An employee receives an email with an urgent message asking for their login credentials. This is an example of what kind of attack?
SQL Injection
DDoS attack
Phishing
Man-in-the-middle
Allowing users to use easily guessable passwords, like “12345,” represents a vulnerability in ____________
Password policy
Patch management
Access control
Encryption
A company network is slow and seems overloaded. The IT team suspects an attack. Which is likely?
Phishing
Man-in-the-middle
DDoS
Keylogger
Which hashing algorithm is currently recommended for secure data hashing due to its resistance to collision attacks?
SHA-256
SHA-1
MD5
AES
Which symmetric encryption algorithm is currently the standard for protecting government data?
AES
Blowfish
RSA
3DES
Which type of encryption uses separate keys for encryption and decryption?
Symmetric encryption
Block encryption
Asymmetric encryption
Stream encryption
A customer service employee receives an email claiming to be from a bank, requesting verification of account details. This is an example of __________
SQL injection
Social engineering
DoS attack
Man-in-the-middle (MitM) attack
An anti-virus software scans for and removes which type of the following threats?
Physical threats
Phishing attempts
Malware
Social engineering attacks
A disgruntled employee with access to sensitive data is considered as __________
A vulnerability
A threat
A risk
A mitigation
What tool might a hacker use to capture and analyze network traffic?
Metasploit
Wireshark
Firewall
VPN
A company installs fences, gates, and security guards at the entrance to its data center. What physical security strategy is this an example of?
Layered security
Risk mitigation
Encryption
Remote access control
What is the primary difference between passive and active attacks?
Passive attacks are illegal; active attacks are legal
Passive attacks observe; active attacks interfere
Active attacks are undetectable
Passive attacks damage the system
In the context of information security, what is a ‘threat’?
A software bug
A potential danger to information systems
A security policy
A virus
An attacker scans a company’s network for open ports and available services without attempting to breach it. This is an example of ____________
Active attack
Passive attack
Social engineering
Phishing
What measures support the confidentiality of customer data? (Choose two)
Strong encryption
Regular backups
Multi-factor authentication
Public Wi-fi access
Which two are examples of human-made threats to information security?
Earthquakes
Malware attacks
Flooding
Phishing scams
Rootkits are easy to detect with standard antivirus software
True
False
Which of the following are common signs of a malware infection? (Choose two)
Frequent updates
Short battery life
Slow system performance
Unexpected pop-up ads
Which algorithm is best suited for generating digital signatures due to its support for key pair generation?
DSA
DES
AES
Blowfish
What encryption algorithm is commonly used to secure Wi-Fi networks in WPA2 encryption?
RSA
AES
DES
MD5
What are two common signs of a phishing email?
Generic greetings like “Dear Customer”
Specific details about a recent conversation
Urgent language requesting immediate action
Familiar senders with exact email addresses
Which of the following describes a white-hat hacker?
A hacker working illegally
An ethical hacker helping improve security
A hacker exploiting vulnerabilities for profit
A hacker targeting government systems
What is a popular hacking tool for simulating network attacks on Windows environments?
MacOS
Window Phone
Ubuntu
Kali Linux
Script kiddies are highly skilled hackers who create sophisticated tools.
True
False
Which type of hacker performs illegal activities for financial gain?
White Hat
Gray Hat
Black Hat
Red Hat
Keyloggers record every keystroke on a device to capture passwords and other data.
True
False
Ransomware attacks typically aim to impact which aspect of the CIA Triad?
Confidentiality
Availability
Authenticity
Integrity
Encryption ensures data integrity by preventing unauthorized access.
True
False
What two measures are important for network availability in a university? (choose two)
Data encryption
Distributed denial-of-service (DDoS) protection
Redundant Internet connections
Public Wi-fi without security
Which malware types typically involve data theft? (Choose two)
Spyware
Keylogger
Worm
Ransomware
A hacker who discloses a security flaw to a company without expecting payment is known as a _______
Ethical hacker
Red-team member
Script kiddie
Gray-hat hacker
An organization implements a backup system to protect against data loss. Which principle of information security does this support?
Integrity
Availability
Confidentiality
Authentication
An organization has adopted a policy where users are only granted access to data necessary for their roles. This approach is known as ___________
Access whitelisting
Principle of least privilege
Data segregation
Open access policy
What is the primary difference between passive and active attacks?
Airplane hijacker
Browser hijacker
Adware
Spyware
An attacker sends a large number of requests to a website, causing it to slow down and become inaccessible. This is an example of what attack?
DoS
Phishing
SQL Injection
Backdoor
What is the purpose of using a firewall in a network?
Encrypts data
Detects malware
Controls incoming and outgoing traffic based on security rules
Manages passwords
A financial institution needs to safeguard its ATMs from physical tampering and vandalism. Which two security measures would be most effective? (Select two)
Anti-skimming devices
Installing network firewalls
Surveillance cameras near ATMs
Regularly updating ATM software
What methods protect data availability during a server outage? (choose two)
Data encryption
Backup servers
Redundant network connections
Strong password policie
An IT administrator configures an Access Control List (ACL) to allow only certain IP addresses to connect to a server. This measure primarily protects against _________
Malware
Data breaches
Phishing
Unauthorized access
Which two principles are at risk when an employee downloads sensitive data onto an unsecured device?
Confidentiality
Integrity
Non-repudiation
Availability
Spyware is often used to collect user data without consent
True
False
What are the three main goals of information security?
Risk, Threat, Vulnerability
Authentication, Authorization, Accounting
Confidentiality, Integrity, Availability
Encryption, Decryption, Firewall
