Worksheets67 Question Sec+ Quiz
Total questions: 58
Worksheet time: 58mins
Which of the following best describes the CIA Triad?
Confidentiality, Integrity, Authentication
Confidentiality, Integrity, Availability
Control, Integrity, Availability
Compliance, Integrity, Authentication
What is the primary function of a firewall?
Encrypting sensitive data
Blocking unauthorized access while permitting legitimate communication
Detecting and removing malware
Managing user authentication
Which attack involves an attacker intercepting and modifying communications between two parties?
Man-in-the-Middle (MitM)
Phishing
Denial-of-Service (DoS)
SQL Injection
What is the purpose of multi-factor authentication (MFA)?
To require users to answer multiple security questions
To ensure users reset their passwords regularly
To provide an additional layer of security by requiring two or more authentication factors
To replace password-based authentication
Which of the following is an example of a physical security control?
Antivirus software
Firewall
Security badge access
Password policy
What type of malware disguises itself as legitimate software to trick users into installing it?
Worm
Trojan Horse
Rootkit
Ransomware
Which security measure is commonly used to prevent brute-force attacks?
Account lockout policy
Antivirus software
Content filtering
Network segmentation
What is the main function of a VPN (Virtual Private Network)?
To detect network intrusions
To provide secure remote access by encrypting data transmission
To prevent unauthorized access to files
To replace traditional firewalls
What does the principle of least privilege (PoLP) state?
Users should have access to all resources on a system
Users should only have the minimum access necessary to perform their job functions
Users must change their passwords every 30 days
Users should be granted administrator rights by default
What is the primary purpose of an Intrusion Detection System (IDS)?
To actively block unauthorized access attempts
To detect and alert on suspicious activity
To replace firewalls in network security
To encrypt network traffic
Which of the following best describes the concept of least privilege?
Users are granted only the minimum access necessary to perform their job functions.
Users are given administrative privileges to troubleshoot system issues.
Users must use multifactor authentication for all logins.
Users have unrestricted access to all resources.
Which of the following is a common technique used in social engineering attacks?
SQL injection
Phishing
MAC filtering
Port scanning
What is the primary purpose of a VPN?
To scan networks for vulnerabilities
To encrypt data transmitted over a network
To prevent malware infections
To block unauthorized access to files
Which of the following attacks involves an attacker inserting malicious code into a website's input fields?
DDoS
Cross-site scripting (XSS)
Man-in-the-middle (MITM)
ARP poisoning
A company wants to implement a security measure that ensures a user's identity is verified based on multiple authentication factors. Which method should they use?
Single sign-on (SSO)
Multifactor authentication (MFA)
Role-based access control (RBAC)
Mandatory access control (MAC)
What is the main purpose of a honeypot in cybersecurity?
To increase network speed
To detect and analyze attacks
To prevent malware infections
To encrypt network traffic
Which of the following cryptographic concepts ensures that data cannot be modified without detection?
Confidentiality
Availability
Integrity
Non-repudiation
A company suspects an insider threat. Which of the following security controls would be most effective in detecting suspicious user activity?
Security information and event management (SIEM)
Data Loss Prevention (DLP)
Antivirus software
Network segmentation
Which of the following encryption algorithms is considered the most secure for modern symmetric encryption?
DES
3DES
AES
RC4
Which type of cryptographic attack attempts to find two different inputs that produce the same hash value?
Brute-force attack
Birthday attack
Side-channel attack
Man-in-the-middle attack
Which key exchange protocol is commonly used in modern cryptographic applications to securely establish shared keys over an insecure channel?
RSA
Diffie-Hellman
MD5
SHA-256
What is the primary purpose of a digital signature?
Encrypt messages for confidentiality
Provide integrity and non-repudiation
Establish a secure communication channel
Generate random cryptographic keys
Which of the following best describes the process of encrypting data with a recipient's public key?
Ensures confidentiality
Provides integrity
Verifies authenticity
Generates a hash
What is the primary function of a certificate authority (CA) in a public key infrastructure (PKI)?
Encrypts messages for secure communication
Issues and manages digital certificates
Provides hashing services
Generates encryption keys
Which cryptographic hashing algorithm is considered the most secure among the following?
MD5
SHA-1
SHA-256
DES
What type of attack is mitigated by using perfect forward secrecy (PFS) in cryptographic protocols?
Brute-force attack
Key compromise attack
SQL injection
Phishing
Which of the following encryption modes should be used to prevent pattern leakage in a block cipher?
ECB (Electronic Codebook)
CBC (Cipher Block Chaining)
OFB (Output Feedback)
CFB (Cipher Feedback)
What is the main advantage of elliptic curve cryptography (ECC) over traditional RSA?
ECC uses symmetric encryption
ECC requires larger key sizes for the same security level
ECC provides strong security with shorter key lengths
ECC is less efficient than RSA
Which of the following is the primary purpose of a risk assessment?
To eliminate all risks in an organization
To identify, analyze, and prioritize risks
To implement security controls without assessing risks
To ensure compliance with security policies
A company purchases cyber liability insurance to cover financial losses from a potential data breach. What type of risk response is this?
Risk transference
Risk avoidance
Risk mitigation
Risk acceptance
Which of the following BEST describes qualitative risk assessment?
Assigning numerical values to risk probabilities and impacts
Using experience and judgment to assess risk severity
Relying solely on financial loss estimates
Calculating the Annualized Loss Expectancy (ALE)
A company's security team calculates that an attack could cost $500,000 and is likely to occur once every 10 years. What is the Annualized Loss Expectancy (ALE)?
$50,000
$100,000
$10,000
$500,000
What is the primary purpose of implementing a Business Impact Analysis (BIA)?
To identify the most critical business functions and their impact if disrupted
To assess compliance with government regulations
To eliminate cybersecurity threats
To replace a risk assessment
Which document defines how an organization will respond to security incidents?
Disaster Recovery Plan (DRP)
Incident Response Plan (IRP)
Business Continuity Plan (BCP)
Risk Register
An IT manager implements additional security controls to reduce the impact of a potential cyberattack. What type of risk treatment is this?
Risk transference
Risk avoidance
Risk mitigation
Risk acceptance
What role does a risk register play in risk management?
It lists security controls implemented in the organization
It records identified risks, their impact, likelihood, and treatment plans
It is used only for financial reporting purposes
It replaces a business continuity plan
A company decides to discontinue a vulnerable application instead of securing it. Which risk management strategy is being used?
Risk acceptance
Risk transference
Risk avoidance
Risk mitigation
What is the primary purpose of a Security Information and Event Management (SIEM) system?
Detect and respond to physical security threats
Centralize log collection and analyze security events
Encrypt stored sensitive information
Prevent zero-day attacks through firewall rules
Which of the following best describes a SOAR (Security Orchestration, Automation, and Response) platform?
A system designed to prevent malware infections
A technology that automates and integrates security response workflows
A software used only for network security monitoring
A database for storing security policies
What is the main advantage of an Endpoint Detection and Response (EDR) solution over traditional antivirus software?
It only detects known malware signatures
It offers real-time monitoring and behavioral analysis
It does not require cloud connectivity
It replaces the need for firewalls
Which of the following best defines the concept of "least privilege"?
Granting users access to all systems for efficiency
Restricting access to only what is necessary for a user’s role
Rotating access permissions weekly
Granting admin rights to all employees
What is the primary function of a Security Operations Center (SOC)?
To develop software security patches
To monitor, analyze, and respond to security threats
To manage an organization's HR policies
To physically secure the data center
Which of the following is the BEST way to protect against insider threats?
Implementing a strict password policy
Conducting regular security awareness training and user activity monitoring
Disabling all USB ports on company devices
Hiring more security personnel
A security analyst notices repeated failed login attempts on a privileged account. What is the BEST immediate action?
Disable the account and investigate the activity
Increase the password complexity requirement
Ignore the attempts unless they succeed
Notify the user to change their password
What is a major security concern with Shadow IT?
It increases IT department efficiency
It creates potential security risks due to unapproved applications and devices
It improves compliance with industry regulations
It reduces attack surface by limiting IT resources
An organization wants to improve its incident response process. Which framework would BEST help establish a structured approach?
ISO 27001
NIST SP 800-61
GDPR
SOC 2
Which type of attack involves overwhelming a target system with excessive requests to render it unavailable?
Phishing
Denial-of-Service (DoS)
Cross-Site Scripting (XSS)
Man-in-the-Middle (MITM)
What is the primary purpose of a buffer overflow attack?
To inject malicious SQL commands
To steal user credentials
To execute arbitrary code on a system
To overload a system with traffic
Which of the following BEST describes a zero-day vulnerability?
A vulnerability that has been patched by the vendor
A vulnerability that remains unpatched and is actively exploited
A vulnerability that requires user interaction to exploit
A vulnerability that only affects legacy systems
Which security control is MOST effective in preventing phishing attacks?
Installing a firewall
Implementing user awareness training
Using network segmentation
Disabling JavaScript in web browsers
An attacker intercepts communication between two parties to eavesdrop or alter messages. Which attack is this?
SQL Injection
Man-in-the-Middle (MITM)
Cross-Site Request Forgery (CSRF)
Credential stuffing
What is the purpose of a honeypot in cybersecurity?
To detect and analyze attack patterns
To provide a secure storage solution
To prevent malware infections
To encrypt sensitive data
Which of the following is an example of an insider threat?
A hacker using SQL injection to steal data
A disgruntled employee leaking sensitive information
A phishing attack targeting employees
A botnet launching a DDoS attack
Which technique is used to mitigate SQL Injection attacks?
Disabling JavaScript in web browsers
Using prepared statements and parameterized queries
Implementing strong password policies
Blocking all outgoing network traffic
What is the primary purpose of network segmentation?
To increase internet speed
To isolate critical systems and limit lateral movement
To prevent phishing attacks
To allow unrestricted access to all users
Which security measure is MOST effective in preventing brute-force attacks on user accounts?
Disabling unused ports
Implementing account lockout policies
Using WEP encryption
Deploying network firewalls
Which of the following best describes a zero-trust architecture?
A security model that assumes all network traffic is safe if it originates internally
A model where users and devices must be continuously verified, regardless of their location
A security model that relies solely on perimeter-based defenses
A model where employees only need to authenticate once for full network access
Which of the following best enhances security in a microservices-based enterprise architecture?
Implementing a monolithic application structure
Using service mesh for secure communication between services
Allowing unrestricted API access for better performance
Eliminating identity and access management (IAM) for internal services
