WorksheetsSec+ Days 1 - 3
Total questions: 44
Worksheet time: 22mins
Which NIST Special Publication series provides guidelines for information security?
SP 800 Series
SP 600 Series
SP 700 Series
SP 300 Series
(blank) Analysis is a process that identifies how an organization's security systems deviate from those required or recommended by a framework. Fill in the blank.
Forensics
Discovery
Security
Gap
This type of Security Control is implemented primarily by people, such as an Incident Response Plan, or a training program.
Managerial
Technical
Operational
Physical
This type of Security Control includes proper lighting.
Technical
Physical
Managerial
Operational
This type of Security Control gives oversight and helps us in our selection of other Security Controls.
Managerial
Operational
Physical
Technical
This type of Security Control includes firewalls and antivirus software.
Operational
Managerial
Physical
Technical
This type of Functional Security Control provides a temporary solution when the existing control is unable to mitigate a disaster.
Deterrent
Directive
Compensating
Corrective
This Information Security Role is responsible for the overall strategy to ensure IT systems align with the organization's goals.
Security Manager
Chief Security Officer
Chief Information Officer
Information Systems Security Officer
This concept focuses on following secure coding practices at every stage of software development and deployment.
Continuous Monitoring
Input Validation
Vulnerability Scanning
DevSecOps
Risk can be calculated by multiplying the (blank) by the (blank).
Threat x Likelihood
Vulnerability x Impact
Likelihood x Impact
Vulnerability x Threat
What type of Threat Actor(s) will typically use APTs?
Script Kiddies
Hacktivist
Nation State
Organized Crime group
This type of Threat Actor is well-funded, operates from different parts of the world, and rakes in a lot of cash in the process.
Skilled Hacker
Nation-State Actors
Organized Crime group
Bryan
The total sum of all the points where an attacker can try to penetrate a network is known as what?
Threat Vector
Attack Surface
Network Topology
Vulnerability Report
This type of vulnerability scan requires software to be installed on all of our network devices.
Credentialed
Non-Credentialed
Client-based
Agentless
This type of Service Provider is a third-party company that delivers IT services to an organization.
IXP
ISP
MSP
PS5
The use of a carefully crafted story with convincing or intimidating details is referred to as (blank).
Impersonating
Phishing
SMishing
Pretexting
Alvin registered "goggle.com" to exploit an error made by users when entering a website address. This is known as (blank).
Typospoofing
Typosquatting
Cross Site Spoofing
SQL Injection
This cryptographic concept literally means "secret writing."
Encryption
Plaintext
Ciphertext
Cryptography
This Cryptographic Concept is the art of cracking cryptographic systems.
Cryptologic Analysis
Ciphertext
Cryptanalysis
CryptoKeeper 2000
This type of Encryption is used for confidentiality.
PKI
Hashing
Symmetric
Asymmetric
This type of Encryption can NEVER provide a mechanism to detect changes or tampering. Choose the best answer.
Symmetric
Asymmetric
Hashing
Invisible ink pen
This Encryption Standard is widely used and offers varying key lengths, such as 128-bit and 256-bit.
DES
AES
RSA
MD5
In Asymmetric Encryption, the (blank) key encrypts the message, and the (blank) key decrypts the message.
Shared / Private
Private / Public
Public / Shared
Alvin's lawnmower key / Bryan's mailbox key
This type of Hashing Algorithm is considered the strongest.
AES
MD5
SHA
RSA
Combining public key cryptography and hashing is used to create (blank).
a Digital Signature
an Encrypted Email
a Message Digest
a Salted Password
This Encryption Algorithm typically uses a key length of at least 2,048 bits.
RSA
ECC
AES
SHA
This entity issues public keys.
Certificate Authority
Cloud Access Security Broker
Key Escrow Agent
Bryan's uncle from Milwaukee
This special type of digital certificate is self-signed by a CA.
Leaf Certificate
Public Certificate
Private Certificate
Root Certificate
What is the primary purpose of a Certificate Signing Request?
To obtain a leaf certificate
To receive a digital key
To receive a digital certificate
All of the above
This Certificate Revocation Reason Code indicates that a certificate is temporarily invalid.
CessationOfOperation
KeyCompromise
Superseded
CertificateHold
Which term refers to a trusted third party holding a copy of encryption keys for the purpose of accessing encrypted data if necessary?
Digital Signature
Public Key Infrastructure (PKI)
Key Exchange
Key Escrow
This term refers to the randomness collected by a system to generate crypto keys.
Ciphertext
Obfuscation
Entropy
Algorithm
I want to send Alvin a large amount of marketing files via email. Which method will best assist me?
Symmetric Encryption
Asymmetric Encryption
File Compression
Hashing
This type of data is present in a CPU register or cache.
Bulk
Data at rest
Data in Transit
Data in use
I want to encrypt everything on my computer, including my OS. What should I use?
FDE
Volume Encryption
Partition Encryption
Filesystem Encryption
This Language is used in Relational Database Management Systems.
HTML
HTML5
SQL
XML
This Language is used to allow remote workers to access their work files through Safari.
VPN
Proxy
SQL
HTML5
This method prevents rainbow table attacks.
Hashing
Salting
Key Stretching
Obfuscation
Embedding text within images is known as what?
Obfuscation
Data Masking
Covert Channels
Steganography
This type of Firewall blocks certain HTTP/HTTPS traffic to and from LinkedIn.
NGFW
WAF
Cloud Firewall
Stateful Inspection Firewalls
All of the above
This type of Firewall uses Stateful Inspection, Deep Packet Inspection, SSL/TLS Decryption, and Intrusion Prevention.
Web Application Firewall
Proxy Firewall
Stateful Inspection Firewall
NGFW
This port on a network switch is configured to copy and send a replica of traffic to a monitoring device.
SPAN
TAP
Trunk
Relay
Which Tunneling Protocol is commonly used to create secure VPNs, protecting data in transit over untrusted networks?
IPSec
TLS
RDP
Proxy
This term involves using a separate, dedicated network path to access and manage network devices when the primary network is down.
Jump Server
SAW
OOB Management
Redundant Pathway
