Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CHAP5

Total questions: 76

Worksheet time: 38mins

Name
Class
Date
1.

Confidentiality is sometimes confused with:

a)

privacy.

b)

authenticity.

c)

integrity.

d)

nonrepudiation.

2.

________ is the ability to ensure that e-commerce participants do

not deny their online actions.

a)

Nonrepudiation

b)

Authenticity

c)

Availability

d)

Integrity

3.

________ is the ability to identify the person or entity with whom

you are dealing on the Internet.

a)

Nonrepudiation

b)

Authenticity

c)

Availability

d)

Integrity

4.

Which of the following is an example of an integrity violation of e-

commerce security?

a)

A website is not actually operated by the entity the customer

believes it to be.

b)

A merchant uses customer information in a manner not intended by

the customer.

c)

A customer denies that he is the person who placed the order.

d)

An unauthorized person intercepts an online communication

and changes its contents.

5.

________ is the ability to ensure that an e-commerce site continues

to function as intended.

a)

Nonrepudiation

b)

Authenticity

c)

Availability

d)

Integrity

6.

Which of the following is an example of an online privacy

violation?

a)

your e-mail being read by a hacker

b)

your online purchasing history being sold to other merchants

without your consent

c)

your computer being used as part of a botnet

d)

your e-mail being altered by a hacker

7.

________ is the ability to ensure that messages and data are only

available to those authorized to view them.

a)

Confidentiality

b)

Integrity

c)

Privacy

d)

Availability

8.

Which of the following is NOT a key factor for establishing e-

commerce security?

a)

data integrity

b)

technology

c)

organizational policies

d)

laws and industry standards

9.

According to Ponemon Institute's 2019 survey, which of the

following was NOT among the causes of the costliest cybercrimes?

a)

malicious insiders

b)

web-based attacks

c)

denial of service

d)

botnets

10.

Typically, the more security measures added to an e-commerce

site, the slower and more difficult it becomes to use.

a)

TRUE

b)

FALSE

11.

Which of the following statements about data breaches in 2019 is

NOT true?

a)

According to the Identity Theft Resource Center, the number of

breaches in 2019 increased by 17% from 2018.

b)

According to the Identity Theft Resource Center, the breaches

exposed almost 165 million sensitive records, such as social security

numbers and financial account data.

c)

According to the Identity Theft Resource Center, employee error

was the leading cause of data breaches.

d)

According to the Identity Theft Resource Center, data breaches

involving the business sector represented about 44% of all breaches.

12.

Which of the following is a brute force attack which hackers

launch via botnets and automated tools using known user name and

password combinations?

a)

credential stuffing

b)

phishing

c)

pharming

d)

MitM attack

13.

Which of the following did the Internet Advertising Bureau urge

advertisers to abandon?

a)

HTML

b)

HTML5

c)

Adobe Flash

d)

Adobe Acrobat

14.

Accessing data without authorization on Dropbox is an example

of a:

a)

social network security issue.

b)

cloud security issue.

c)

mobile platform security issue.

d)

sniffing issue.

15.

All of the following can be considered a direct or indirect competitor of Amazon EXCEPT:

a)

eBay.

b)

Target.

c)

Walmart

d)

Priceline.

16.

Conficker is an example of a:

a)

virus.

b)

worm.

c)

Trojan horse.

d)

botnet.

17.

Which of the following is the leading cause of data breaches?

a)

theft of a computer

b)

accidental disclosures

c)

hackers

d)

DDoS attacks

18.

Software that is used to obtain private user information such as a

user's keystrokes or copies of e-mail is referred to as:

a)

spyware.

b)

a backdoor.

c)

a browser parasite.

d)

adware.

19.

Which of the following technologies is aimed at reducing e-mail

address spoofing and phishing?

a)

TLS

b)

WPA

c)

DMARC

d)

MFA

20.

What is the most frequent cause of stolen credit cards and card

information today?

a)

lost cards

b)

the hacking and looting of corporate servers storing credit card

information

c)

sniffing programs

d)

phishing attacks

21.

Which dimensions of security is spoofing a threat to?

a)

integrity and confidentiality

b)

availability and authenticity

c)

integrity and authenticity

d)

availability and integrity

22.

Which of the following is NOT an example of malicious code?

a)

scareware

b)

Trojan horse

c)

bot

d)

sniffer

23.

The attack against Dyn servers is an example of a(n):

a)

scareware

b)

Trojan horse

c)

bot

d)

sniffer

24.

Beebone is an example of which of the following?

a)

worm

b)

botnet

c)

phishing

d)

hacktivism

25.

Malware that comes with a downloaded file requested by a user is

called a:

a)

Trojan horse.

b)

backdoor.

c)

drive-by download.

d)

PUP.

26.

Which of the following is not an example of a potentially

unwanted program (PUP)?

a)

adware

b)

browser parasite

c)

drive-by download

d)

spyware

27.

Which of the following was designed to cripple Iranian nuclear

centrifuges?

a)

Stuxnet

b)

Shamoon

c)

Snake

d)

Storm

28.

Automatically redirecting a web link to a different address is an

example of which of the following?

a)

sniffing

b)

social engineering

c)

pharming

d)

DDoS attack

29.

Which of the following types of attacks enabled hackers to take

control of the Twitter accounts of dozens of America’s most

prominent political, entertainment and technology leaders?

a)

DDoS attack

b)

ransomware

c)

social engineering

d)

sniffing

30.

________ typically attack governments, organizations, and

sometimes individuals for political purposes.

a)

Crackers

b)

Tiger teams

c)

Bounty hunters

d)

Hacktivists

31.

A Trojan horse appears to be benign, but then does something

other than expected.

a)

TRUE

b)

FALSE

32.

Phishing attacks rely on browser parasites.

a)

TRUE

b)

FALSE

33.

WannaCry is an example of ransomware.

a)

TRUE

b)

FALSE

34.

Spoofing is the attempt to hide a hacker's true identity by using

someone else's e-mail or IP address.

a)

TRUE

b)

FALSE

35.

Exploit kits can be purchased by users to protect their computers

from malware.

a)

TRUE

b)

FALSE

36.

A drive-by download is malware that comes with a downloaded

file that a user intentionally or unintentionally requests.

a)

TRUE

b)

FALSE

37.

FREAK is an example of a software vulnerability.

a)

TRUE

b)

FALSE

38.

Next generation firewalls provide all of the following EXCEPT:

a)

an application-centric approach to firewall control.

b)

the ability to identify applications regardless of the port, protocol,

or security evasion tools used.

c)

the ability to automatically update applications on a client

computer with security patches.

d)

the ability to identify users regardless of the device or IP address.

39.

Asymmetric key cryptography is also known as:

a)

public key cryptography.

b)

secret key cryptography.

c)

PGP.

d)

PKI.

40.

All the following statements about symmetric key cryptography

are true EXCEPT:

a)

in symmetric key cryptography, both the sender and the receiver

use the same key to encrypt and decrypt a message.

b)

the Data Encryption Standard is a symmetric key encryption

system.

c)

symmetric key cryptography is computationally slower.

d)

symmetric key cryptography is a key element in digital envelopes.

41.

The Data Encryption Standard uses a(n) ________-bit key.

a)

8

b)

56

c)

256

d)

512

42.

All of the following statements about public key cryptography are

true EXCEPT:

a)

public key cryptography uses two mathematically related digital

keys.

b)

public key cryptography ensures authentication of the sender.

c)

public key cryptography does not ensure message integrity.

d)

public key cryptography is based on the idea of irreversible

mathematical functions.

43.

All of the following are features of WPA3 EXCEPT:

a)

it implements a more robust key exchange protocol.

b)

it enables the creation of a VPN.

c)

it provides a more secure way to connect IoT devices.

d)

it features expanded encryption for public networks.

44.

All of the following statements about PKI are true EXCEPT:

a)

the term PKI refers to the certification authorities and digital

certificate procedures that are accepted by all parties.

b)

PKI is not effective against insiders who have a legitimate access

to corporate systems including customer information.

c)

PKI guarantees that the verifying computer of the merchant is

secure.

d)

the acronym PKI stands for public key infrastructure.

45.

A digital certificate contains all of the following EXCEPT the:

a)

subject's private key.

b)

subject's public key.

c)

digital signature of the certification authority.

d)

digital certificate serial number.

46.

Which of the following dimensions of e-commerce security is

NOT provided for by encryption?

a)

confidentiality

b)

availability

c)

message integrity

d)

nonrepudiation

47.

All of the following are methods of securing channels of

communication EXCEPT:

a)

TLS.

b)

digital certificates.

c)

VPN.

d)

FTP.

48.

A ________ is hardware or software that acts as a filter to prevent

unwanted packets from entering a network.

a)

firewall

b)

virtual private network

c)

proxy server

d)

PPTP

49.

Proxy servers are also known as __________ because they have

two network interfaces.

a)

firewalls

b)

application gateways

c)

dual home systems

d)

packet filters

50.

All of the following are used for authentication EXCEPT:

a)

digital signatures.

b)

certificates of authority.

c)

biometric devices.

d)

packet filters.

51.

An intrusion detection system can perform all of the following

functions EXCEPT:

a)

examining network traffic.

b)

setting off an alarm when suspicious activity is detected.

c)

checking network traffic to see if it matches certain patterns or

preconfigured rules.

d)

blocking suspicious activity.

52.

Which of the following is not an example of an access control?

a)

firewalls

b)

proxy servers

c)

digital signatures

d)

login passwords

53.

Which of the following statements is NOT true?

a)

A VPN provides both confidentiality and integrity.

b)

A VPN uses both authentication and encryption.

c)

A VPN uses a dedicated secure line.

d)

The primary use of VPNs is to establish secure communications

among business partners.

54.

Which of the following statements is NOT true?

a)

Apple's Touch ID stores a digital replica of a user's actual

fingerprint in Apple's iCloud

b)

Biometric devices reduce the opportunity for spoofing.

c)

A retina scan is an example of a biometric device.

d)

Biometric data stored on an iPhone is encrypted.

55.

Face ID is an example of which of the following?

a)

biometrics

b)

encryption

c)

IDS

d)

firewall

56.

Which of the following is the most common protocol for securing

a digital channel of communication?

a)

DES

b)

TLS

c)

VPN

d)

HTTP

57.

Most computers and mobile devices today have built-in

encryption software that users can enable.

a)

TRUE

b)

FALSE

58.

The easiest and least expensive way to prevent threats to system

integrity is to install anti-virus software.

a)

TRUE

b)

FALSE

59.

What is the first step in developing an e-commerce security plan?

a)

Create a security organization.

b)

Develop a security policy.

c)

Perform a risk assessment.

d)

Perform a security audit.

60.

To allow lower-level employees access to the corporate network

while preventing them from accessing private human resources

documents, you would use:

a)

a firewall.

b)

an authorization management system.

c)

security tokens.

d)

an authorization policy.

61.

Which of the following statements is NOT true?

a)

A majority of states require companies that maintain personal data

on their residents to publicly disclose when a security breach affecting

those residents has occurred.

b)

The USA Patriot Act broadly expanded law enforcement's

investigative and surveillance powers.

c)

The Cybersecurity Information Sharing Act was strongly

supported by most large technology companies and privacy

advocates.

d)

The Federal Trade Commission has asserted that it has authority

over corporations' data security practices.

62.

Zero trust is a cybersecurity framework based on the principle of

maintaining strict access controls and not trusting anyone or anything

by default, even those behind a corporate firewall.

a)

TRUE

b)

FALSE

63.

Which of the following statements about blockchain is not true?

a)

A blockchain system is composed of a distributed network of

computers.

b)

A blockchain system is inherently centralized.

c)

A blockchain system is a transaction processing system.

d)

Cryptocurrencies are based on blockchain technology.

64.

All of the following statements about Apple Pay are true EXCEPT

which of the following?

a)

Apple Pay is the most popular alternative payment method in the

United States.

b)

Apple Pay is an example of a universal proximity mobile wallet.

c)

Apple Pay can be used for mobile payments at the point of sale at a

physical store.

d)

Apple Pay has more users than either Google Pay or Samsung Pay.

65.

PayPal is an example of which of the following types of payment

system?

a)

online stored value payment system

b)

digital checking system

c)

accumulating balance system

d)

digital credit card system

66.

PCI-DSS is a standard established by which of the following?

a)

the banking industry

b)

the credit card industry

c)

the federal government

d)

the retail industry

67.

Which of the following is NOT a major trend in e-commerce

payments in 2020-2021?

a)

Online payment volume decreases due to the Covid-19 pandemic.

b)

PayPal remains the most popular alternative payment method.

c)

Large banks enter the mobile wallet and P2P payments market.

d)

Payment by credit and/or debit card remains the dominant form of

online payment.

68.

All of the following are limitations of the existing online credit

card payment system EXCEPT:

a)

poor security.

b)

cost to consumers.

c)

cost to merchant.

d)

social equity.

69.

Which of the following statements about Bitcoin is NOT true?

a)

The computational power required to mine Bitcoins has increased

over time.

b)

Bitcoins are completely secure.

c)

Bitcoins are illegal in some countries.

d)

Bitcoin mining uses more energy than the entire amount consumed

by Switzerland.

70.

Which of the following is a set of short-range wireless

technologies used to share information among devices within about

two inches of each other?

a)

DES

b)

NFC

c)

IM

d)

text messaging

71.

All of the following are examples of cryptocurrencies EXCEPT:

a)

Ethereum.

b)

Ripple.

c)

Zelle.

d)

Monero.

72.

Zelle is an example of a P2P mobile payment app.

a)

TRUE

b)

FALSE

73.

Bluetooth is the primary enabling technology for mobile wallets.

a)

TRUE

b)

FALSE

74.

There is a finite number of Bitcoins that can be created.

a)

TRUE

b)

FALSE

75.

Mint Bills is an example of which of the following EBPP business

models?

a)

biller-direct

b)

online banking

c)

consolidator

d)

mobile

76.

According to the most recent Fiserv survey, 65% of consumers in

the United States have used online bill payment.

a)

TRUE

b)

FALSE