wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Sec+ | 1.4 Encryptions | 701

Total questions: 20

Worksheet time: 21mins

Name
Class
Date
1.

This is a cryptographic technology that uses a key to convert plain text data into cipher text data. The data is transmitted as cipher text, and then once reaching its destination is reverted back to the original plain text form. The purpose of this technology is to ensure data is SECURE/PRIVATE/CONFIDENTIAL.

a)

Encryption

b)

Hash

c)

Salt

d)

Rainbow Table

2.

A mathematical function that takes data of any size and produces a fixed-size string of characters, essentially acting like a unique "fingerprint" of that data. It is used to verify the integrity of information and detect any changes made to it.

a)

Publik Key Infrastructure (PKI)

b)

Encryption

c)

Key Stretching

d)

Hash

3.

If an employee at IP Cyber is denied access to a file that they want to access, which part of the CIA triad is being enforced?

a)

Confidentiality

b)

Integrity

c)

Availability

4.

If a threat actor breaks into our systems and is attempting to collect credential information (username/passwords) data from one of our databases, which of these cryptographic technologies would reduce the impact of their attack?

a)

Availability

b)

Hashing

c)

Backups

d)

Common Vulnerabilities and Exposures (CvE)

5.

This is a a random string of data added to a password or other sensitive information before it is hashed to add complexity. It also helps an enterprise defeat a threat actors capability to use a rainbow table.

a)

Data Loss Prevention (DLP)

b)

Waterfall Model

c)

RFID Tokens

d)

Salting

6.

This is a technique used to hide data in an image file.

a)

Data Tokenization

b)

Steganography

c)

Data Masking

d)

Encryption

7.

Our company has a massive amount of sensitive customer data that has been archived. As a safety protocol, we have encrypted this data to ensure that it cannot be read by anyone who should not have access. What is the state of the data we are protecting?

a)

Data-in-Transit

b)

Data-at-Rest

c)

Data-in-Use

8.

The policy of Least Privilege controls the amount of access rights employees have within our organization. What part of the CIA triad would this security control influence?

a)

Integrity

b)

Availability

c)

Confidentiality

9.

IP Cyber is planning to allow employees to work from home (remote-work) and wants to ensure that when they connect to the companies resources, they are connecting through a secure medium that encrypts all traffic. They have chosen to use a Virtual Private Network (VPN). What state is the data that the employees are accessing through the VPN considered to be in?

a)

Data-at-Rest

b)

Data-in-Transit

c)

Data-in-Processing

10.

IP Cyber is going to use Full Disk Encryption (FDE) on all employee-issued laptops to ensure all data on each laptop is as secure as possible in the event that a laptop is stolen. This means IP Cyber needs to store a copy of each employees keys somewhere. Where is a good place to store cryptographic keys for this purpose?

a)

Key Hole

b)

Key Exchange

c)

Key Escrow

d)

Key Agreement

11.

IP Cyber is using a software tool that continuously checks files for changes and unusual behavior. It ensures that all critical system files are authentic and can be trusted. What is his type of tool known as?

a)

Security Orchestration and Automation Response (SOAR)

b)

Security Information and Event Management (SIEM)

c)

File Integrity Monitoring (FIM)

d)

Encryption

12.

IP Cyber wants to ensure that they are properly managing and storing clients login information in their systems. Their goal is to reduce the chance that an attacker will be able to use the data if stolen to break into peoples accounts. They have opted to use this technology to safely store credentials so that plain-text versions would not be compromised in the event of a data-breach.

a)

Federation

b)

Isolation

c)

Hashing

d)

Segmentation

13.

Our company wants to ensure that remote workers can connect safely and securely from their home network to the companies network. They need to choose a technology that will allow them to complete their tasks through an encrypted tunnel. Which of these should they choose?

a)

Hypervisor Type II

b)

Hypervisor Type I

c)

Virtual Machine (VM)

d)

Virtual Private Network (VPN)

14.

Martin wants to ensure that the software he downloaded from the Apache website has not been changed or altered in any way by a malicious threat actor. Which technology would he use to check the authenticity and integrity of the Apache software file he downloaded?

a)

Rainbow Table

b)

Salt

c)

Encryption

d)

Hash

15.

IP Cyber has collected a great deal of personal data about their employees to include their names, date of birth, social security information and tax data. Additionally, they have collected healthcare information to allow enrollment into a healthcare plan. What types of data are being stored?

a)

FDE and ARO

b)

PKI and PHI

c)

PII and DLP

d)

PII and PHI

16.

After collecting their employees information, including the PII and PHI data and storing the data, the security team at IP Cyber wants to ensure that no one tampers with these sensitive files. What tool can they use to monitor these files for changes, and get an alert if anything suspicious occurs?

a)

SIEM

b)

Encryption

c)

FIM

d)

Hash

17.

Which of these technologies greatly increase the strength and complexity of passwords, making it very difficult for an attacker to decrypt them?

a)

GDPR

b)

Attestation

c)

Key Escrow

d)

Salt

18.

IP Cyber has collected credit card information from its customer base, and has stored this data in their database in a way that complies with PCI DSS regulatory requirements. They have chosen to replace all sensitive card data with a special "placeholder". What technique are they using?

a)

Encryption

b)

Steganography

c)

Data masking

d)

Data tokenization

19.

Encryption algorithms are used as a CONFIDENTIALITY security control, which ultimately controls who can access a data set or structure. Align the properties with the proper terms.

Categorize the following

More Secure

Less Secure

FASTER

SLOWER

1-Key System

2-Key System

Alice and Bob use this one

Symmetric
Asymmetric
20.

IP Cyber needs a security chip installed directly onto the motherboard of a computer that protects that device by storing cryptographic keys and other sensitive information from cyber attacks. What is this device called?

a)

Trusted Platform Module (TPM)

b)

Hardware Security Module (HSM)

c)

Key Agreement

d)

Encryption