NEW
Font size
WorksheetsISF 2
Total questions: 20
Worksheet time: 10mins
What is an example of a vulnerability in a cybersecurity context?
Weak encryption on stored data
Strong password policies
Regular software updates
Two-factor authentication
Which cybersecurity measure ensures secure communication with suppliers?
Use virtual private networks (VPNs)
Implement firewalls
Conduct regular security audits
Utilize antivirus software
What is ransomware?
A type of malware that encrypts data for ransom
A software that speeds up computer performance
A program that removes viruses from a system
A tool for managing network traffic
Which factor makes polymorphic malware particularly challenging for traditional antivirus programs?
It constantly changes its code signature to evade detection
It is always distributed through email attachments
It can only infect Windows operating systems
It requires user interaction to execute
Sensitive emails sent without encryption could lead to:
Data breaches
Increased email delivery speed
Improved user experience
Enhanced data storage
What is one key feature of polymorphic malware?
It changes its code to evade detection
It is designed to spread rapidly across networks
It requires user interaction to activate
It is always detected by antivirus software
How do you change permissions in absolute mode?
. chmod numeric_value
chmod -R value
chmod +x filename
chmod 777 filename
A critical reason for using two-factor authentication is:
Adding an additional layer of security
Making passwords longer
Reducing the need for passwords
Eliminating the risk of phishing attacks
Which of the following is an example of a technical security control?
Firewall configuration
Security policy documentation
Employee training programs
Physical access controls
In the context of intrusion detection logs, organizations should:
Regularly analyze and act on them
Ignore them unless an incident occurs
Only review them annually
Store them without analysis
What are the two most commonly used malware families in the Healthcare industry, according to FIREEYE?
XtremeRAT and WITCHCOVEN
Trojan and Ransomware
Adware and Spyware
WannaCry and Emotet
What is the purpose of the CISA Services Catalog?
To provide a centralized document with cybersecurity services and alerts
To list all cybersecurity professionals in the country
To serve as a guide for cybersecurity training programs
To outline the history of cybersecurity threats
Why is PowerShell frequently used in malware attacks?
It provides a command-line interface to execute scripts
It is a graphical user interface for managing files
It is a web-based application for remote access
It is a programming language for developing software
Which method can help reduce data exfiltration in case of a network breach?
Using Data Loss Prevention (DLP) tools to monitor and restrict sensitive data transfers.
Implementing stronger password policies for user accounts.
Increasing the bandwidth of the network to handle more traffic.
Regularly updating software to patch vulnerabilities.
What is a common countermeasure for preventing brute-force attacks?
Implementing strong password policies and account lockouts
Using simple passwords for easier access
Allowing unlimited login attempts
Disabling two-factor authentication
Which cybersecurity model assumes that no user or device should be trusted by default?
Zero Trust model
Trusted Network model
Defense in Depth model
Perimeter Security model
Which of the following would be classified as a vulnerability in a cybersecurity risk assessment?
A software bug that allows unauthorized access to sensitive data.
A strong password policy that prevents unauthorized access.
Regular software updates to patch security flaws.
A firewall that blocks unauthorized network traffic.
What is a common attack that exploits weak passwords?
Phishing attack
Brute-force attack
SQL injection
Man-in-the-middle attack
Which of the following vulnerabilities allows attackers to access systems without formal authorization?
Unauthorized privilege escalation
SQL injection
Cross-site scripting
Buffer overflow
What is a common cybersecurity risk associated with remote learning and hybrid workspaces?
Increased risk of physical theft of devices
Greater exposure to phishing and video conferencing attacks
Higher chances of malware from USB drives
Reduced need for strong passwords
