Font size
WorksheetsSec+ | 1.4 Encryptions | 701
Total questions: 20
Worksheet time: 21mins
This is a cryptographic technology that uses a key to convert plain text data into cipher text data. The data is transmitted as cipher text, and then once reaching its destination is reverted back to the original plain text form. The purpose of this technology is to ensure data is SECURE/PRIVATE/CONFIDENTIAL.
Encryption
Hash
Salt
Rainbow Table
A mathematical function that takes data of any size and produces a fixed-size string of characters, essentially acting like a unique "fingerprint" of that data. It is used to verify the integrity of information and detect any changes made to it.
Publik Key Infrastructure (PKI)
Encryption
Key Stretching
Hash
If an employee at IP Cyber is denied access to a file that they want to access, which part of the CIA triad is being enforced?
Confidentiality
Integrity
Availability
If a threat actor breaks into our systems and is attempting to collect credential information (username/passwords) data from one of our databases, which of these cryptographic technologies would reduce the impact of their attack?
Availability
Hashing
Backups
Common Vulnerabilities and Exposures (CvE)
This is a a random string of data added to a password or other sensitive information before it is hashed to add complexity. It also helps an enterprise defeat a threat actors capability to use a rainbow table.
Data Loss Prevention (DLP)
Waterfall Model
RFID Tokens
Salting
This is a technique used to hide data in an image file.
Data Tokenization
Steganography
Data Masking
Encryption
Our company has a massive amount of sensitive customer data that has been archived. As a safety protocol, we have encrypted this data to ensure that it cannot be read by anyone who should not have access. What is the state of the data we are protecting?
Data-in-Transit
Data-at-Rest
Data-in-Use
The policy of Least Privilege controls the amount of access rights employees have within our organization. What part of the CIA triad would this security control influence?
Integrity
Availability
Confidentiality
IP Cyber is planning to allow employees to work from home (remote-work) and wants to ensure that when they connect to the companies resources, they are connecting through a secure medium that encrypts all traffic. They have chosen to use a Virtual Private Network (VPN). What state is the data that the employees are accessing through the VPN considered to be in?
Data-at-Rest
Data-in-Transit
Data-in-Processing
IP Cyber is going to use Full Disk Encryption (FDE) on all employee-issued laptops to ensure all data on each laptop is as secure as possible in the event that a laptop is stolen. This means IP Cyber needs to store a copy of each employees keys somewhere. Where is a good place to store cryptographic keys for this purpose?
Key Hole
Key Exchange
Key Escrow
Key Agreement
IP Cyber is using a software tool that continuously checks files for changes and unusual behavior. It ensures that all critical system files are authentic and can be trusted. What is his type of tool known as?
Security Orchestration and Automation Response (SOAR)
Security Information and Event Management (SIEM)
File Integrity Monitoring (FIM)
Encryption
IP Cyber wants to ensure that they are properly managing and storing clients login information in their systems. Their goal is to reduce the chance that an attacker will be able to use the data if stolen to break into peoples accounts. They have opted to use this technology to safely store credentials so that plain-text versions would not be compromised in the event of a data-breach.
Federation
Isolation
Hashing
Segmentation
Our company wants to ensure that remote workers can connect safely and securely from their home network to the companies network. They need to choose a technology that will allow them to complete their tasks through an encrypted tunnel. Which of these should they choose?
Hypervisor Type II
Hypervisor Type I
Virtual Machine (VM)
Virtual Private Network (VPN)
Martin wants to ensure that the software he downloaded from the Apache website has not been changed or altered in any way by a malicious threat actor. Which technology would he use to check the authenticity and integrity of the Apache software file he downloaded?
Rainbow Table
Salt
Encryption
Hash
IP Cyber has collected a great deal of personal data about their employees to include their names, date of birth, social security information and tax data. Additionally, they have collected healthcare information to allow enrollment into a healthcare plan. What types of data are being stored?
FDE and ARO
PKI and PHI
PII and DLP
PII and PHI
After collecting their employees information, including the PII and PHI data and storing the data, the security team at IP Cyber wants to ensure that no one tampers with these sensitive files. What tool can they use to monitor these files for changes, and get an alert if anything suspicious occurs?
SIEM
Encryption
FIM
Hash
Which of these technologies greatly increase the strength and complexity of passwords, making it very difficult for an attacker to decrypt them?
GDPR
Attestation
Key Escrow
Salt
IP Cyber has collected credit card information from its customer base, and has stored this data in their database in a way that complies with PCI DSS regulatory requirements. They have chosen to replace all sensitive card data with a special "placeholder". What technique are they using?
Encryption
Steganography
Data masking
Data tokenization
Encryption algorithms are used as a CONFIDENTIALITY security control, which ultimately controls who can access a data set or structure. Align the properties with the proper terms.
More Secure
Less Secure
FASTER
SLOWER
1-Key System
2-Key System
Alice and Bob use this one
IP Cyber needs a security chip installed directly onto the motherboard of a computer that protects that device by storing cryptographic keys and other sensitive information from cyber attacks. What is this device called?
Trusted Platform Module (TPM)
Hardware Security Module (HSM)
Key Agreement
Encryption
