Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Sec+ Days 1 - 3

Total questions: 44

Worksheet time: 22mins

Name
Class
Date
1.

Which NIST Special Publication series provides guidelines for information security?

a)

SP 800 Series

b)

SP 600 Series

c)

SP 700 Series

d)

SP 300 Series

2.

(blank) Analysis is a process that identifies how an organization's security systems deviate from those required or recommended by a framework. Fill in the blank.

a)

Forensics

b)

Discovery

c)

Security

d)

Gap

3.

This type of Security Control is implemented primarily by people, such as an Incident Response Plan, or a training program.

a)

Managerial

b)

Technical

c)

Operational

d)

Physical

4.

This type of Security Control includes proper lighting.

a)

Technical

b)

Physical

c)

Managerial

d)

Operational

5.

This type of Security Control gives oversight and helps us in our selection of other Security Controls.

a)

Managerial

b)

Operational

c)

Physical

d)

Technical

6.

This type of Security Control includes firewalls and antivirus software.

a)

Operational

b)

Managerial

c)

Physical

d)

Technical

7.

This type of Functional Security Control provides a temporary solution when the existing control is unable to mitigate a disaster.

a)

Deterrent

b)

Directive

c)

Compensating

d)

Corrective

8.

This Information Security Role is responsible for the overall strategy to ensure IT systems align with the organization's goals.

a)

Security Manager

b)

Chief Security Officer

c)

Chief Information Officer

d)

Information Systems Security Officer

9.

This concept focuses on following secure coding practices at every stage of software development and deployment.

a)

Continuous Monitoring

b)

Input Validation

c)

Vulnerability Scanning

d)

DevSecOps

10.

Risk can be calculated by multiplying the (blank) by the (blank).

a)

Threat x Likelihood

b)

Vulnerability x Impact

c)

Likelihood x Impact

d)

Vulnerability x Threat

11.

What type of Threat Actor(s) will typically use APTs?

a)

Script Kiddies

b)

Hacktivist

c)

Nation State

d)

Organized Crime group

12.

This type of Threat Actor is well-funded, operates from different parts of the world, and rakes in a lot of cash in the process.

a)

Skilled Hacker

b)

Nation-State Actors

c)

Organized Crime group

d)

Bryan

13.

The total sum of all the points where an attacker can try to penetrate a network is known as what?

a)

Threat Vector

b)

Attack Surface

c)

Network Topology

d)

Vulnerability Report

14.

This type of vulnerability scan requires software to be installed on all of our network devices.

a)

Credentialed

b)

Non-Credentialed

c)

Client-based

d)

Agentless

15.

This type of Service Provider is a third-party company that delivers IT services to an organization.

a)

IXP

b)

ISP

c)

MSP

d)

PS5

16.

The use of a carefully crafted story with convincing or intimidating details is referred to as (blank).

a)

Impersonating

b)

Phishing

c)

SMishing

d)

Pretexting

17.

Alvin registered "goggle.com" to exploit an error made by users when entering a website address. This is known as (blank).

a)

Typospoofing

b)

Typosquatting

c)

Cross Site Spoofing

d)

SQL Injection

18.

This cryptographic concept literally means "secret writing."

a)

Encryption

b)

Plaintext

c)

Ciphertext

d)

Cryptography

19.

This Cryptographic Concept is the art of cracking cryptographic systems.

a)

Cryptologic Analysis

b)

Ciphertext

c)

Cryptanalysis

d)

CryptoKeeper 2000

20.

This type of Encryption is used for confidentiality.

a)

PKI

b)

Hashing

c)

Symmetric

d)

Asymmetric

21.

This type of Encryption can NEVER provide a mechanism to detect changes or tampering. Choose the best answer.

a)

Symmetric

b)

Asymmetric

c)

Hashing

d)

Invisible ink pen

22.

This Encryption Standard is widely used and offers varying key lengths, such as 128-bit and 256-bit.

a)

DES

b)

AES

c)

RSA

d)

MD5

23.

In Asymmetric Encryption, the (blank) key encrypts the message, and the (blank) key decrypts the message.

a)

Shared / Private

b)

Private / Public

c)

Public / Shared

d)

Alvin's lawnmower key / Bryan's mailbox key

24.

This type of Hashing Algorithm is considered the strongest.

a)

AES

b)

MD5

c)

SHA

d)

RSA

25.

Combining public key cryptography and hashing is used to create (blank).

a)

a Digital Signature

b)

an Encrypted Email

c)

a Message Digest

d)

a Salted Password

26.

This Encryption Algorithm typically uses a key length of at least 2,048 bits.

a)

RSA

b)

ECC

c)

AES

d)

SHA

27.

This entity issues public keys.

a)

Certificate Authority

b)

Cloud Access Security Broker

c)

Key Escrow Agent

d)

Bryan's uncle from Milwaukee

28.

This special type of digital certificate is self-signed by a CA.

a)

Leaf Certificate

b)

Public Certificate

c)

Private Certificate

d)

Root Certificate

29.

What is the primary purpose of a Certificate Signing Request?

a)

To obtain a leaf certificate

b)

To receive a digital key

c)

To receive a digital certificate

d)

All of the above

30.

This Certificate Revocation Reason Code indicates that a certificate is temporarily invalid.

a)

CessationOfOperation

b)

KeyCompromise

c)

Superseded

d)

CertificateHold

31.

Which term refers to a trusted third party holding a copy of encryption keys for the purpose of accessing encrypted data if necessary?

a)

Digital Signature

b)

Public Key Infrastructure (PKI)

c)

Key Exchange

d)

Key Escrow

32.

This term refers to the randomness collected by a system to generate crypto keys.

a)

Ciphertext

b)

Obfuscation

c)

Entropy

d)

Algorithm

33.

I want to send Alvin a large amount of marketing files via email. Which method will best assist me?

a)

Symmetric Encryption

b)

Asymmetric Encryption

c)

File Compression

d)

Hashing

34.

This type of data is present in a CPU register or cache.

a)

Bulk

b)

Data at rest

c)

Data in Transit

d)

Data in use

35.

I want to encrypt everything on my computer, including my OS. What should I use?

a)

FDE

b)

Volume Encryption

c)

Partition Encryption

d)

Filesystem Encryption

36.

This Language is used in Relational Database Management Systems.

a)

HTML

b)

HTML5

c)

SQL

d)

XML

37.

This Language is used to allow remote workers to access their work files through Safari.

a)

VPN

b)

Proxy

c)

SQL

d)

HTML5

38.

This method prevents rainbow table attacks.

a)

Hashing

b)

Salting

c)

Key Stretching

d)

Obfuscation

39.

Embedding text within images is known as what?

a)

Obfuscation

b)

Data Masking

c)

Covert Channels

d)

Steganography

40.

This type of Firewall blocks certain HTTP/HTTPS traffic to and from LinkedIn.

a)

NGFW

b)

WAF

c)

Cloud Firewall

d)

Stateful Inspection Firewalls

e)

All of the above

41.

This type of Firewall uses Stateful Inspection, Deep Packet Inspection, SSL/TLS Decryption, and Intrusion Prevention.

a)

Web Application Firewall

b)

Proxy Firewall

c)

Stateful Inspection Firewall

d)

NGFW

42.

This port on a network switch is configured to copy and send a replica of traffic to a monitoring device.

a)

SPAN

b)

TAP

c)

Trunk

d)

Relay

43.

Which Tunneling Protocol is commonly used to create secure VPNs, protecting data in transit over untrusted networks?

a)

IPSec

b)

TLS

c)

RDP

d)

Proxy

44.

This term involves using a separate, dedicated network path to access and manage network devices when the primary network is down.

a)

Jump Server

b)

SAW

c)

OOB Management

d)

Redundant Pathway